Google Professional Cloud Security Engineer Exam Guide (2026)

If you can say whether the stem is buying an identity, a perimeter, a data control, or a posture finding, you are reading the right outline.
Professional Cloud Security Engineer is the Google Cloud certification for people who design and implement secure workloads and infrastructure on Google Cloud. The Professional Cloud Security Engineer certification page is the source for length, fee, question count, and recommended experience. The Professional Cloud Security Engineer exam guide is the source for the five scored sections and the product names used on the sitting.
The sitting is live. There is no prerequisite exam. Google recommends 3 or more years of industry experience, including more than 1 year designing and managing solutions using Google Cloud. This guide is for people scheduling the current standard exam, people who already hold the title and need the current task list, and people moving from Associate Cloud Engineer work into the security-engineer role.
Who this exam is for
Take it as a map of the Google Cloud security job the current exam guide scores. The audience profile asks for someone who can hold identity, hold a perimeter, hold encryption, and then stay with production when a finding or a regulation arrives. The same profile expects Google security technologies, not a private toolchain the sitting never names.
The responsibility list on the certification page is concrete. Configure access. Secure communications and establish boundary protection. Ensure data protection. Manage operations. Support compliance requirements. Those five verbs are the five scored sections. The sitting punishes people who treat the role as a catalog of logos and rewards people who can read a constraint and pick the identity, the boundary, the key, and the finding that match it.
There is no required prior certification. The recommended experience is the gap check. If projects, Identity and Access Management roles, Cloud Storage buckets, and gcloud are still a catalog rather than weekly work, sit Associate Cloud Engineer first. The security sitting assumes those controls and then asks which principal, which perimeter, and which key to recommend. If the goal is the language of Google Cloud rather than the operation of a secure estate, Cloud Digital Leader is the closer match. Service definitions, shared responsibility, and product families belong there. They appear here as the vocabulary inside a control, not as the whole job.
Skip it if the work you actually want is deploying someone else's design day to day without owning the identity, the perimeter, or the key. That job is Associate Cloud Engineer. Skip it if the work you actually want is the compute shape, the network path, and a named case-study constraint across an entire solution. Those decisions are the Professional Cloud Architect sitting. Security products appear there as one recommendation among many. They are scored here as the entire job. Skip it if the stem you actually want is a Cloud Build trigger, an SLO, or a PromQL query. Supply-chain gates appear on this outline as Binary Authorization and CVE scanning. They are not the Professional Cloud DevOps Engineer sitting. Skip it if the stem you actually want is a Beam job or a warehouse reservation. Sensitive Data Protection appears here as a discovery and redaction control. It is not the Professional Data Engineer sitting. Skip it if the work you actually want is writing detection rules, hunting threats, and running a security operations platform. That title is Professional Security Operations Engineer.
The current professional security-engineer credential Google publishes for this role is this one. Use this page for the Professional Cloud Security Engineer task list. Use the Google Associate Cloud Engineer exam guide when the stem is an operator control that happens to sit on a firewall. Use the Google Professional Cloud Architect exam guide when the stem is a solution recommendation that happens to include a key. Use the Google Professional Cloud DevOps Engineer exam guide when the stem is a pipeline stage rather than a security control. Use the Google Professional Data Engineer exam guide when the stem is a data platform rather than a data-protection control.
Exam shape and how a pass is decided
The current exam guide publishes five sections and marks each weight as an approximation.
| Section | Weight | What gets tested |
|---|---|---|
| Configuring access | about 25% | Cloud Identity, Google Cloud Directory Sync, SSO, super administrator accounts, user lifecycle, programmatic users and groups, Workforce Identity Federation, service accounts including defaults, service account keys, short-lived credentials, Workload Identity Federation, impersonation, password and session policy, SAML and OAuth, 2-step verification, IAM roles and permissions, ACLs, IAM conditions, IAM deny policies, least privilege at organization, folder, project, and resource, Access Context Manager, Policy Intelligence, groups, Privileged Access Manager, folders and projects at scale, organization policies, and hierarchy inheritance |
| Securing communications and establishing boundary protection | about 22% | Cloud Next Generation Firewall rules and policies, Identity-Aware Proxy, load balancers, Certificate Authority Service, layer 7 inspection on Cloud NGFW, private versus public IP addressing, Google Cloud Armor, Secure Web Proxy, Cloud DNS security settings, restricted APIs, VPC networks, VPC Network Peering, Shared VPC, firewall rules, N-tier isolation, VPC Service Controls, Private Google Access, Private Google Access for on-premises hosts, restricted Google access, Private Service Connect, HA VPN, Cloud Interconnect, and Cloud NAT |
| Ensuring data protection | about 23% | Sensitive Data Protection, PII discovery and redaction, pseudonymization, format-preserving encryption, restricted access to BigQuery, Cloud Storage, and Cloud SQL, Secret Manager, compute instance metadata, Google default encryption, customer-managed encryption keys, Cloud External Key Manager, software versus hardware keys, key rotation, revocation, key import, Cloud Storage object lifecycle policies, Confidential Computing, AI and ML security and privacy, IaaS-hosted and PaaS-hosted training models, and security controls for Gemini Enterprise Agent Platform |
| Managing operations | about 19% | CVE scanning in a CI/CD pipeline, Binary Authorization on GKE or Cloud Run, image hardening, VM patch management, cloud security posture management, custom organization policies, custom modules for Security Health Analytics, Cloud NGFW logs, VPC Flow Logs, Packet Mirroring, Cloud Intrusion Detection System, Log Analytics, logging strategy, incident response, secure access to logs, export to external security systems, Cloud Audit Logs, data access logs, log sinks, aggregated sinks, and Security Command Center |
| Supporting compliance requirements | about 11% | Technical needs for compute, data, network, and storage, the shared responsibility model, Assured Workloads, organization policies, Access Transparency, Access Approval, regionalization of data and services, the in-scope environment, and mapping requirements to Google Cloud services and controls including network and access segmentation and audit log coverage |
Do the arithmetic on those approximations before building a plan. The five midpoints total 100%. Google still prints a tilde on every band, so no exact split exists to memorize. Section 1 is the heaviest band. Section 3 sits next. Section 2 sits next. Section 4 sits next. Section 5 is the lightest band. Any study plan that gives five equal weeks overweights compliance and underweights access and data protection.
The logistics come off the certification page. The standard sitting is 2 hours. The format is 50 to 60 multiple choice and multiple select questions. Languages are English and Japanese. The registration fee is 200 USD, and tax where applicable. Delivery is online-proctored from a remote location or onsite-proctored at a testing center. Prerequisites are none. The certification page does not print a Validity period field this pass. Google Cloud Certification Exam Policies and Exam Terms and Conditions say a Professional Certification is valid for two years from the date of issue.
Case studies are not a scored share on this sitting. The certification page and the official exam guide PDF name no companies and no case-study percentage. Do not study a fifth company a dump site invented. Do not carry Professional Cloud Architect case-study habits onto this timer as if they were official here.
Scoring is the part most third-party pages get wrong. The certification page and the exam guide do not publish a numeric passing score, a scaled range, or a percent hedge. Exam Terms and Conditions say that if you pass an Exam, you will receive a digital certificate after Google has validated your score. That is the official pass language. This guide does not invent a 700 mark or a 70 percent story for a vendor that did not publish one.
The same terms page is the source for retakes and for how long the credential lasts. Associate and Professional exams allow a maximum of four attempts in a two year period. After a failed attempt, the wait is 14 days. After a second failed attempt, the wait is 60 days. After a third failed attempt, the wait is 365 days before a fourth attempt. Each attempt requires payment. Passing a Professional exam during renewal extends validity for two years from the date of passing.
Renewal on this title follows the exam path. Professional renewal eligibility on the terms page begins 60 days before expiration. The certification page sends holders to Renewal FAQs for the eligibility window. That page does not publish a shorter 1 hour sitting, a 20 question count, or a 100 USD fee for this title. Do not invent those numbers from a different Google exam. After the eligibility window, the path back is the standard exam.
Two more details change how the sitting is taken. Google may update exam content at any time to reflect changes to Google Cloud technology. The certifications hub says exams are being updated for product updates announced at Google Cloud Next '26, including Gemini Enterprise Agent Platform and Google Cloud's data and analytics stack. The current Professional Cloud Security Engineer guide already scores security controls for Gemini Enterprise Agent Platform in section 3.3. The product names that matter on this timer are the names on the current exam guide, not the names on last month's console banner.
What the current outline changed
The exam guide does not publish a Microsoft-style change-log table. The official delta is the set of names the current pages print.
The certification page for this title does not open with a branding-change banner this pass. The exam guide is still the place to review the product names used on the exam. The current guide already says Workforce Identity Federation, Workload Identity Federation, Privileged Access Manager, Policy Intelligence, Access Context Manager, IAM deny policies, Cloud NGFW, Google Cloud Armor, Secure Web Proxy, Certificate Authority Service, VPC Service Controls, Private Service Connect, Sensitive Data Protection, Cloud External Key Manager, Confidential Computing, Gemini Enterprise Agent Platform, Binary Authorization, Security Health Analytics, Cloud IDS, and Assured Workloads.
The certifications hub is more specific about the product wave. Exams are being updated to reflect product updates announced at Google Cloud Next '26, including Gemini Enterprise Agent Platform and Google Cloud's data and analytics stack. The current Professional Cloud Security Engineer guide already puts Gemini Enterprise Agent Platform on the data-protection section. A study plan that treats that name as an optional extra is studying last year's job.
Current product docs have already moved some of those names. The sitting has not finished every move.
| Name on the exam guide | Name on current first-party docs | What that means on the sitting |
|---|---|---|
| Sensitive Data Protection (SDP) | Sensitive Data Protection. The API is still named Cloud Data Loss Prevention API | A PII discovery or redaction stem is Sensitive Data Protection on the outline |
| Artifact Analysis | Artifact Analysis, formerly Container Analysis. The new name does not change existing products or APIs | A vulnerability-scan stem is still Artifact Analysis on the outline |
| Cloud NGFW | Cloud Next Generation Firewall, with Essentials, Standard, and Enterprise tiers | A packet or layer 7 inspection stem is Cloud NGFW, not a leftover VPC-only firewall story |
| Gemini Enterprise Agent Platform | Gemini Enterprise Agent Platform, with security controls that vary by feature | An AI-workload security stem that names that platform is section 3.3, not a DevOps Gemini assistant stem |
| Privileged Access Manager | Privileged Access Manager, just-in-time elevation with entitlements and grants | A standing Owner role is the weaker control when the outline named temporary elevation |
| Cloud EKM | Cloud External Key Manager, key material that stays outside Google | A key Google must never hold is Cloud EKM, not a software CMEK |
Validity and renewal changed the calendar around the sitting even when the five section names stayed close. Professional Cloud Security Engineer lasts 2 years on the terms page. Foundational and Associate credentials last 3 years on the same page. Mixing those clocks is how people schedule the wrong renewal door.
Three things follow for anyone holding older material.
The five section names are still the spine. Access, communications and boundary, data protection, operations, and compliance are still the scored map. Notes organized on those five headings are still structurally useful.
The product names inside those headings are in motion. Privileged Access Manager, Cloud NGFW, Sensitive Data Protection, and Gemini Enterprise Agent Platform are the names the exam guide prints. A flashcard that only knows last year's console label, and cannot map it back to the outline, is already off the current PDF.
This sitting has no official case-study PDFs. Time spent on invented company names is time taken from sections 1 and 3.
How access gets picked
Section 1 is about 25%, the heaviest band, and the same discriminator shows up in perimeter stems and compliance stems as often as in identity ones. Section 1.1 already named Cloud Identity, Directory Sync, and Workforce Identity Federation. Section 1.2 then scores the service account. Section 1.4 scores the authorization control.

IAM overview says IAM lets you control who can do what on which resources. A grant has three parts. A principal is the identity. A role is the collection of permissions. A resource is the thing being accessed. You grant the role on the resource with an allow policy. Allow policies inherit down the resource hierarchy. The organization is the root. Folders sit under the organization or under another folder. Projects sit under the organization or a folder. Service resources sit under projects. A role on a container applies to the children. The union of the resource policy and every ancestor policy is the effective allow policy.
Principals split into two families on that page. Human users include Google Accounts, Google groups, and federated identities in workforce identity pools. Workloads include service accounts and federated identities in a workload identity pool. Treating those two families as one principal type is how section 1 is lost.
Overview of Cloud Identity is the user and group directory that then receives IAM roles. The exam guide pairs Cloud Identity with Google Cloud Directory Sync and SSO to a third-party identity provider. Workforce Identity Federation lets users in an external IdP reach Google Cloud with SSO. It does not store those user accounts in Google Cloud. It is sync-less. The same page says you do not need Cloud Identity's Google Cloud Directory Sync when you federate this way. It supports IdPs that speak OIDC or SAML 2.0, including Microsoft Entra ID, AD FS, and Okta. Workforce identity pools are configured at the organization. A stem about employees who must sign in through an existing IdP without a second copy of every user is Workforce Identity Federation. A stem about keeping a synchronized Google Account for every employee is Directory Sync. Those are two answers.
Workload Identity Federation is the other federation. It lets a GitHub Action, a GitLab job, an AWS workload, or another supporting IdP reach Google Cloud without a downloaded service account key. The Workforce page states the split in one sentence. Workforce Identity Federation federates user identities. Workload Identity Federation federates workload identities. A stem about a person is Workforce. A stem about a pipeline or a VM outside Google Cloud is Workload.
Service accounts overview is the identity for an application or a compute workload, not a person. User-managed service accounts are the ones you create. Default service accounts are created automatically when you enable certain services, and you still manage them. Service agents are created and managed by Google Cloud. The page warns that service account keys are a security risk if they are not managed correctly. Prefer an attached service account, short-lived credentials, impersonation, or Workload Identity Federation. The default Compute Engine and App Engine service accounts receive the Editor role on the project when they are created. Disable automatic role grants for default service accounts. A service account is both a principal and a resource. Granting a human the Service Account Token Creator role on a powerful service account is impersonation, and that human then holds everything the service account can hold. A stem about a JSON key in a repository is already the weaker control when the outline named short-lived credentials or federation.
Privileged Access Manager overview is just-in-time elevation. You create an entitlement. A principal requests a grant. Privileged Access Manager adds the time-bound IAM binding and removes it when the grant ends. Entitlements work on projects, folders, and organizations. IAM Conditions can narrow an entitlement. The product supports Cloud Identity, Workforce Identity Federation, Workload Identity Federation, and agent identities. It does not support the legacy basic roles Owner, Editor, and Viewer. A stem about a standing Owner grant for break-glass work is the trap when the outline already named Privileged Access Manager.
Deny policies block a permission even when an allow policy would grant it. Overview of IAM Conditions adds an attribute such as time or resource to an allow binding. Access Context Manager Overview defines access levels from attributes such as IP, device, and user context. Those access levels are then used by Identity-Aware Proxy and VPC Service Controls. Policy Intelligence overview is how you analyze and tighten IAM policies. Organization Policy overview constrains what configurations are allowed. That is a different question from who is allowed. About resource hierarchy is organization, optional folders, then projects. A stem about inheritance is the hierarchy. A stem about a forbidden configuration is an organization policy. A stem about a forbidden permission is a deny policy. A stem about a role that is valid only during a change window is an IAM condition. A stem about a device or IP check in front of an app is Access Context Manager.
| Control | What the stem is buying | First Google Cloud product | What it does not do well |
|---|---|---|---|
| Human directory | A Google Account or group that will receive roles | Cloud Identity | A workload identity |
| Sync | A second copy of every user in Google | Google Cloud Directory Sync | A sync-less federation |
| Workforce | Employees who already have an external IdP | Workforce Identity Federation | A GitHub job |
| Workload | A pipeline or VM that must not download a key | Workload Identity Federation | A person signing in |
| Service account | An application identity inside Google Cloud | Service accounts | A human login |
| Key file | A downloaded JSON credential | Service account keys | The first answer when federation exists |
| Impersonation | A human who must become the service account | Service account impersonation | A standing Owner role |
| Elevation | Temporary extra permissions with an audit trail | Privileged Access Manager | A permanent Editor grant |
| Deny | Block a permission even if a role allows it | IAM deny policies | A substitute for least privilege |
| Condition | A role that is valid only when an attribute matches | IAM Conditions | A device posture check by itself |
| Access level | IP, device, or context in front of an app or API | Access Context Manager | A packet filter |
| Guardrail | A configuration that must stay forbidden | Organization policies | Who may call the API |
Read the constraint the stem is buying. A contractor who must sign in through Okta is Workforce Identity Federation. A GitHub Action that must push an image is Workload Identity Federation. A Compute Engine instance that must read a bucket is an attached service account. A break-glass hour on a production project is Privileged Access Manager. A permission that must stay blocked even for project Owners is a deny policy. A folder that must not create service account keys is an organization policy.
How a perimeter gets picked
Section 2 is about 22%. The same habit shows up in compliance stems that ask for network and access segmentation. The skill is small. Name whether the stem is buying a packet filter, an application identity check, an edge WAF, an egress proxy, a service perimeter, or a private path to a Google API.

Cloud NGFW overview is the distributed, stateful firewall for Google Cloud workloads. It inspects north-south traffic that enters or leaves a VPC and east-west traffic among resources inside VPC networks. Controls sit at Layer 3, Layer 4, and Layer 7. Essentials is the foundational tier for IP ranges, ports, and protocols. Standard adds features such as fully qualified domain names and threat intelligence. Enterprise adds application-layer inspection, including URL filtering and intrusion detection and prevention. Hierarchical, global, and regional firewall policies exist. Firewall policies and rules is the page for those policy objects. A stem about allowing TCP 443 from one subnet to another is Cloud NGFW. A stem about inspecting HTTP hosts and blocking a URL category is Cloud NGFW Enterprise. Putting that URL filter on Google Cloud Armor because both products say "web" is the trap when the traffic never hits a load balancer.
Cloud Armor overview helps protect deployments from DDoS attacks and application attacks such as cross-site scripting and SQL injection. Security policies are collections of rules applied to requests destined for a protected resource. Preconfigured WAF rules help mitigate OWASP Top 10 risks. Always-on Layer 3 and Layer 4 DDoS protection sits on supported load balancers. Layer 7 HTTP flood protection needs a configured security policy. Policies attach at the edge, close to the traffic source, so unwanted requests never consume the VPC. A stem about SQLi on a public HTTPS load balancer is Google Cloud Armor. A stem about east-west traffic between two private GKE Services is Cloud NGFW.
Identity-Aware Proxy overview is the identity-aware front door. Users prove who they are. Access Context Manager can add the device or IP access level. IAP is not a packet filter and it is not a WAF signature set. A stem about employees reaching an internal web app without a VPN client is IAP. A stem about blocking a /24 at the subnet is Cloud NGFW.
Secure Web Proxy overview is the explicit egress proxy for internet-bound traffic. The exam guide names it next to Cloud NAT. Cloud NAT overview lets private VMs start outbound connections. Cloud NAT does not inspect URLs. Secure Web Proxy does. A stem about private VMs that must reach the internet is Cloud NAT. A stem about those same VMs reaching only approved URLs is Secure Web Proxy.
Certificate Authority Service overview is the managed private certificate authority. Private CAs issue X.509 certificates that carry entity identity, issuer identity, and a cryptographic signature. Private certificates authenticate users, machines, and services on networks the public Web PKI does not cover. CA pools hold one or more CAs and raise issuance throughput. A stem about issuing internal certificates for microservices is Certificate Authority Service. A stem about a public HTTPS certificate on a load balancer is not that product.
VPC Service Controls overview builds service perimeters around Google Cloud services so data in Cloud Storage, BigQuery, and similar APIs cannot leave an authorized boundary. That is a different control from a VPC firewall rule. A firewall rule decides which packets move. A service perimeter decides which Google APIs a project may call and which identities may take data out. A stem about a compromised VM copying a bucket to an unauthorized project is VPC Service Controls. A stem about that VM opening TCP 22 from the internet is Cloud NGFW.
Private connectivity is section 2.3. Shared VPC designates a host project and attaches service projects so those projects use subnets in the host network. VPC Network Peering connects two VPC networks on private addresses. Private Google Access lets VMs without external IPs reach Google APIs. Private Service Connect lets consumers use their own internal addresses to reach services or Google APIs without leaving the VPC. Cloud VPN overview and Cloud Interconnect overview are the hybrid paths from a data center. HA VPN is the exam-guide name for the encrypted hybrid path. Cloud Interconnect is the dedicated or partner path. A stem about one network for many application projects is Shared VPC. A stem about a private endpoint to a Google API is Private Service Connect. A stem about encrypting a data-center path is HA VPN. Flattening every team into one project to make logging easier is the trap when the outline already named Shared VPC and multi-project controls.
DNS Security Extensions (DNSSEC) overview is the Cloud DNS security setting the exam guide points at. A stem about signed DNS responses is DNSSEC. A stem about blocking a hostname at egress is Secure Web Proxy or Cloud NGFW Enterprise.
| Control | What the stem is buying | First Google Cloud product | What it does not replace |
|---|---|---|---|
| Packet filter | Allow or deny by IP, port, or protocol | Cloud NGFW | A WAF on a public load balancer |
| Layer 7 inspect | URL category or intrusion prevention inside the VPC | Cloud NGFW Enterprise | Identity-Aware Proxy |
| Edge WAF | SQLi, XSS, or DDoS on a public load balancer | Google Cloud Armor | East-west micro-segmentation |
| App identity | A person must prove who they are before the app | Identity-Aware Proxy | A subnet firewall rule |
| Egress proxy | Approved URLs for private VMs | Secure Web Proxy | Cloud NAT by itself |
| Outbound NAT | Private VMs that must start internet connections | Cloud NAT | URL filtering |
| Private CA | Internal certificates for machines or services | Certificate Authority Service | A public load-balancer cert |
| Service perimeter | Stop data leaving Google APIs | VPC Service Controls | A VPC firewall rule |
| Shared network | Many projects on one host network | Shared VPC | VPC Network Peering |
| Private API path | Internal addresses to Google APIs or published services | Private Service Connect | A public VIP |
| Hybrid encrypt | A data center that must reach the VPC | HA VPN | A service perimeter |
| Dedicated hybrid | A private link from a data center | Cloud Interconnect | A software VPN |
Read the constraint. A subnet that must talk to another subnet on 443 is Cloud NGFW. A public checkout page that must reject SQLi is Google Cloud Armor. An internal admin app that must see a corporate identity is Identity-Aware Proxy. A bucket that must not leave the perimeter is VPC Service Controls. A private VM that must call a Google API on a private address is Private Service Connect. A data center that must encrypt the path is HA VPN.
How data protection gets picked
Section 3 is about 23%, the second-heaviest band. Most of those questions reduce to one skill. Name whether the stem is buying discovery of sensitive data, a readable secret, a key you manage, a key that never enters Google, or encryption while the CPU is working.

Sensitive Data Protection overview helps you discover, classify, and de-identify sensitive data inside and outside Google Cloud. Discovery profiles scan BigQuery, Cloud SQL, and Cloud Storage for uncatalogued sensitive data. Inspection jobs report every instance of an infoType, such as a credit card number in a bucket. De-identification can mask, redact, bucket, shift dates, or tokenize. The exam guide names discovering and redacting personally identifiable information, configuring pseudonymization, and format-preserving encryption. Findings can go to BigQuery, Pub/Sub, and Security Command Center. The API is still named Cloud Data Loss Prevention API. A stem about finding national identifiers in a warehouse is Sensitive Data Protection. A stem about storing the API key the app must read is Secret Manager. Those are two answers.
Secret Manager overview stores API keys, passwords, and certificates as versions you can roll back. Secrets are encrypted in transit with TLS and at rest with AES-256. Customer-managed keys are optional. Regional secrets exist for data residency. A stem about a password the application must read is Secret Manager. A stem about encrypting a disk with a key you cannot export is Cloud KMS. Putting the password in Compute Engine instance metadata is the trap section 3.1 already named when it asked you to protect that metadata.
Cloud Key Management Service overview lets you create and manage cryptographic keys for compatible Google Cloud services and for your own applications. You can generate software or hardware keys, import existing keys, or link external keys. Customer-managed encryption keys wrap the data encryption keys used by integrated services. That wrapping is envelope encryption. Google default encryption is included, requires no configuration, and uses Google-owned keys you cannot view or manage. Software CMEKs are FIPS 140-2 Level 1 validated in the table on that page. Hardware Cloud HSM keys are FIPS 140-2 Level 3 validated. Cloud External Key Manager keeps key material in a compatible external key manager. Keys are never sent to Google. Compatible services connect to the external manager over the internet or a VPC. If the external key is unavailable, decrypt fails. A stem about encryption that just works is Google default encryption. A stem about rotating a key you own inside Google Cloud is CMEK. A stem about a key Google must never hold is Cloud EKM. A stem about a hardware boundary inside Google Cloud is Cloud HSM. Treating those four as one "customer key" story is how section 3.2 is lost.
Confidential Computing overview is encryption in use. Encryption at rest protects stored data. Encryption in transit protects data that is moving. Confidential Computing protects data while it is being processed, inside a hardware trusted execution environment. Confidential VM is the Compute Engine product in that family. A stem about memory that the hypervisor must not read is Confidential Computing. A stem about a disk that must use your Cloud KMS key is CMEK. Those are two states of the same sentence on the outline, encryption at rest versus encryption in use.
Object Lifecycle Management is the Cloud Storage control the exam guide prints next to encryption. A stem about deleting or changing storage class after a number of days is a lifecycle policy. A stem about who may read the object is IAM or an ACL. A stem about whether the object may leave the project is VPC Service Controls.
Section 3.3 is the AI-workload bullet. The exam guide asks for security and privacy controls that protect against unintentional exploitation of data or models, security requirements for IaaS-hosted and PaaS-hosted training models, and security controls for Gemini Enterprise Agent Platform. Security controls for machine learning services lists data residency, CMEK, VPC Service Controls, and Access Transparency for Gemini Enterprise Agent Platform features. Coverage varies by feature. RAG Engine and Vector Search do not receive every control. The certifications hub already said exams are being updated for Gemini Enterprise Agent Platform. This sitting already scores it. A stem about training data that must stay in a region is data residency. A stem about a model that must use your key is CMEK. A stem about prompts that must not leave a service perimeter is VPC Service Controls. Naming Gemini Code Assist because another Google exam printed that name is the trap. Gemini Code Assist is not a section 3.3 product on this outline.
| Control | What the stem is buying | First Google Cloud product | What it does not replace |
|---|---|---|---|
| Discover | Find PII or PHI in a table or bucket | Sensitive Data Protection | A password store |
| De-identify | Redact, tokenize, or preserve format | Sensitive Data Protection | CMEK |
| Secret | A value the app must read | Secret Manager | A key you cannot export |
| Default encrypt | Encryption with no customer key work | Google default encryption | A key you can disable |
| CMEK | A key you own inside Google Cloud | Cloud KMS customer-managed keys | A key that never enters Google |
| Hardware key | FIPS Level 3 inside Google Cloud | Cloud HSM | Cloud EKM |
| External key | Key material that stays outside Google | Cloud External Key Manager | A software CMEK |
| Encrypt in use | Memory the hypervisor must not read | Confidential Computing | Encryption at rest |
| Lifecycle | Delete or change class after time | Cloud Storage object lifecycle | Who may read the object |
| AI control | Residency, CMEK, VPC-SC, or Access Transparency on Agent Platform | Gemini Enterprise Agent Platform security controls | Gemini Code Assist |
Read the constraint. A column of personal identifiers is Sensitive Data Protection. A database password is Secret Manager. A bucket that must die if you disable your key is CMEK. A key that must stay in an on-premises HSM is Cloud EKM. A training job whose memory must stay encrypted is Confidential Computing. An Agent Platform feature that must stay inside a perimeter is VPC Service Controls on that platform.
How operations and compliance get picked
Section 4 is about 19%. Section 5 is about 11%. Together they ask the same follow-up after access, perimeter, and data are already chosen. Name whether the stem is buying a scan, a deploy-time gate, a misconfiguration finding, a network sensor, an audit trail, or a regulated folder.
Artifact Analysis overview is the scan. The service was formerly Container Analysis. The new name does not change existing products or APIs. Vulnerability scanning is based in Artifact Registry. A stem about CVEs on an image the pipeline just pushed is Artifact Analysis. Blocking the deploy of that image is Binary Authorization.
Binary Authorization overview implements software supply-chain security when you develop and deploy container applications. Enforcement allows only images that conform to a policy you define. Continuous validation can watch running Pods and write Cloud Logging entries when they drift. Supported platforms on that page include GKE, Cloud Run, Cloud Service Mesh, and Google Distributed Cloud. Attestations certify that an image completed a previous stage. At deploy time the policy checks the attestation instead of repeating the stage. The exam guide names Binary Authorization for GKE clusters or Cloud Run. A stem about "only images the pipeline signed may reach prod" is Binary Authorization. Scanning the image and then deploying it anyway is the trap when the stem asked for the gate.
About Patch is the VM Manager page for patching virtual machines. The exam guide names VM patch management next to image hardening. A stem about a golden image is hardening. A stem about a running fleet that must take a CVE patch is Patch.
Security Command Center overview is the risk-management surface. It helps prevent, detect, and respond to security issues. Vulnerability detection covers misconfigurations, exposed resources, and compliance against benchmarks such as NIST, HIPAA, PCI-DSS, and CIS. Findings can export to BigQuery and Pub/Sub. Built-in services, integrated Google Cloud services, and registered third-party services all write findings. Overview of Security Health Analytics is the built-in detection service that scans cloud resources for common misconfigurations. Most of those findings map to security-standard controls. Custom modules for Security Health Analytics are named on the exam guide. A stem about a public Cloud Storage bucket finding is Security Health Analytics inside Security Command Center. A stem about a packet that looks like an exploit is Cloud IDS.
Cloud IDS overview inspects traffic for threats. VPC Flow Logs records network flows. Packet Mirroring copies packets to an inspection target. Cloud Audit Logs overview is who did what. Route log entries is the sink page. A sink can send the same entry to a custom bucket, Cloud Storage, BigQuery, or Pub/Sub, including a destination in another project. Aggregated sinks are how a folder or organization collects those entries. A stem about "who changed the IAM policy" is Cloud Audit Logs. A stem about last year's audit logs in a cheap bucket is a Cloud Storage sink. A stem about a third-party SIEM is a Pub/Sub sink. A stem about bytes between two VMs is VPC Flow Logs. A stem about full packets for a sensor is Packet Mirroring. A stem about a threat signature on a NIC is Cloud IDS.
Section 5 then asks you to place those controls under a regulation. Google security overview states the shared responsibility model. You are responsible for securing what you bring to the cloud. Google is responsible for protecting the cloud itself. You are always responsible for your data. Google is responsible for the underlying infrastructure. In IaaS, hardware, storage, and network sit with Google and more of the stack sits with you. In SaaS, more of the stack sits with Google and you still hold the data and its access. A stem about who patches the hypervisor is Google. A stem about who encrypts the table with CMEK is you.
Overview of Assured Workloads configures a sovereign data and access boundary with residency, access, and personnel controls. You apply a predefined control package to a folder. Control packages include regional data boundaries and regulatory data boundaries such as FedRAMP Moderate, FedRAMP High, CJIS, ITAR, and healthcare controls. The folder then enforces organization policy constraints and related guardrails on every project under it. Overview of Access Transparency lets you view logs of authorized Google personnel activity. Overview of Access Approval requires an authorized administrator in your organization to approve a request before a Google administrator receives access. Approved requests are logged with Access Transparency logs. A stem about data that must stay in the EU is an Assured Workloads regional boundary. A stem about seeing what Google staff did is Access Transparency. A stem about approving that access first is Access Approval. Treating those three words as synonyms is how section 5 is lost.
| Control | What the stem is buying | First Google Cloud product | What it does not replace |
|---|---|---|---|
| Scan | CVEs on a stored image | Artifact Analysis | The deploy-time gate |
| Gate | Only attested images may run | Binary Authorization | The scanner |
| Patch | A running VM that must take a fix | VM Manager Patch | A new golden image by itself |
| Finding | A misconfiguration mapped to a benchmark | Security Health Analytics | A packet capture |
| Posture | The place those findings land | Security Command Center | A SIEM export by itself |
| Flow | Bytes between endpoints | VPC Flow Logs | Full packet payloads |
| Mirror | Packets copied to a sensor | Packet Mirroring | A flow record |
| IDS | A threat signature on traffic | Cloud IDS | A WAF on a load balancer |
| Audit | Who did what | Cloud Audit Logs | A VPC flow record |
| Sink | Keep, analyze, or export the log | Logging sinks | A reason to skip exclusions |
| Shared duty | Who owns the hypervisor versus the data | Shared responsibility model | A control package |
| Regulated folder | Residency, personnel, and key guardrails | Assured Workloads | A single organization policy |
| Google staff log | What Google personnel did | Access Transparency | Customer approval |
| Google staff gate | Approve Google access first | Access Approval | The customer IAM policy |
Read the constraint. A new digest with a CVE is Artifact Analysis. A cluster that must reject an unsigned digest is Binary Authorization. A public bucket finding is Security Health Analytics. A support engineer who must be approved before opening a disk is Access Approval. A folder that must stay in a FedRAMP High boundary is Assured Workloads. Naming Security Command Center for every one of those is how the operations band is wasted.
How to study the current blueprint
Order the weeks by the weight bands, not by the order the products appear in a catalog.
Week 1. Access, the band near 25%. Create a Cloud Identity group and grant it a predefined IAM role on a folder. Grant the same role on one project and write down what each child inherited. Create a custom role with two permissions and compare it with a basic role. Add an IAM condition that is valid only during a change window. Attach a deny policy that blocks resourcemanager.projects.setIamPolicy for a test principal. Create a user-managed service account, attach it to a Compute Engine instance, and reach a Cloud Storage bucket without a key file. Create a short-lived credential and an impersonation binding. Turn on Workload Identity Federation for a GitHub repository so the pipeline does not download a JSON key. If you have an external IdP, configure a workforce identity pool and write down that this is not Workload Identity Federation. Create a Privileged Access Manager entitlement that grants a time-bound role with justification. Apply an organization policy that disables service account key creation. Open Policy Intelligence on a project and tighten one over-grant. Define one Access Context Manager access level from an IP range.
Week 2. Data protection, the band near 23%. Run a Sensitive Data Protection inspection on a BigQuery table or a Cloud Storage bucket and read one infoType finding. Configure a de-identification transform that redacts or tokenizes a field. Store a database password in Secret Manager and read it from a service account. Create a Cloud KMS key ring and a software CMEK, then encrypt a Cloud Storage bucket with that key. Disable the key and confirm the object cannot be read. Open the Cloud EKM page and write down that the key material never enters Google. Start a Confidential VM and write down that this is encryption in use, not CMEK. Set an object lifecycle rule that changes class after 30 days. Open the Gemini Enterprise Agent Platform security-controls page and write down which features list data residency, CMEK, VPC Service Controls, and Access Transparency.
Week 3. Perimeter, the band near 22%. Create a Shared VPC host project and attach one service project. Write a Cloud NGFW policy that allows 443 between two subnets and denies the rest. If you can enable an Enterprise feature, add a layer 7 inspection rule and write down that this is not Google Cloud Armor. Put a public HTTPS load balancer in front of a test service and attach a Cloud Armor security policy with a preconfigured WAF rule. Place Identity-Aware Proxy in front of an internal app and bind it to an Access Context Manager access level. Create a VPC Service Controls perimeter around a Cloud Storage project and try an unauthorized copy. Create a Private Service Connect endpoint to a Google API. Create Cloud NAT for a private subnet, then compare that path with Secure Web Proxy. Create a CA pool in Certificate Authority Service and issue one private certificate. Sketch HA VPN versus Cloud Interconnect on paper and name which one the stem is buying when it says encrypted hybrid path.
Week 4. Operations near 19%, compliance near 11%, and a full review. Push a container to Artifact Registry and turn on Artifact Analysis. Read one vulnerability finding. Create a Binary Authorization policy that requires an attestation before GKE or Cloud Run will take the image. Open Security Command Center and classify one Security Health Analytics finding. Enable VPC Flow Logs on a subnet. Read a Cloud Audit Logs entry for an IAM change. Create a log sink to Cloud Storage and a sink to Pub/Sub and write down why those destinations are different. Create an Assured Workloads folder for a regional or regulatory control package in a test organization if you have access, or walk the supported-package list if you do not. Open Access Transparency and Access Approval and write down the difference. Then sit with the exam guide and, for each bullet, name the product, the boundary, and the constraint that would have forced that product.
Take any official sample questions the certification page still mentions and walk the exam tutorial at least once before using this outline against a clock. The sample set exists so the question format costs nothing on the timer. This guide does not reprint those items.
Traps that look like easy elimination
Security items rarely give one plausible answer and three absurd ones. They give two controls that both sound correct and one detail that picks between them.
- There is no prerequisite certification. Recommended experience is still 3 or more years, including more than 1 year designing and managing solutions using Google Cloud. Showing up with only vocabulary from Cloud Digital Leader is how sections 1 and 3 are lost.
- The standard sitting is 50 to 60 questions in 2 hours. Notes that quote a 40 to 50 question professional sitting are quoting a different exam.
- Google does not publish a numeric passing score on the certification page or the exam guide. A third-party 700 or 70 percent figure is not official language for this sitting.
- This sitting has no official case-study PDFs. A company name that does not appear on the exam guide is not part of the outline.
- Workforce Identity Federation is for people. Workload Identity Federation is for workloads. Directory Sync is the copy of those people into Google Accounts. Those are three answers.
- A service account key is the weaker control when the outline named short-lived credentials, impersonation, or Workload Identity Federation.
- Privileged Access Manager is temporary elevation. A standing Owner role is not the same control.
- An organization policy constrains configuration. An IAM role constrains who. A deny policy can block a permission even when a role allows it.
- Cloud NGFW filters packets and can inspect layer 7 inside the VPC. Google Cloud Armor is the edge WAF and DDoS control on a load balancer. Identity-Aware Proxy is the identity front door. Those are three answers.
- Secure Web Proxy inspects egress URLs. Cloud NAT only translates outbound connections.
- VPC Service Controls protect Google APIs from exfiltration. A VPC firewall rule does not replace a service perimeter.
- Shared VPC is one host network for many projects. VPC Network Peering is a private link between two networks. Private Service Connect is a private endpoint to a service or a Google API.
- Sensitive Data Protection discovers and de-identifies data. Secret Manager stores a value the app must read. Cloud KMS holds a key you cannot export.
- Google default encryption, CMEK, Cloud HSM, and Cloud EKM are four key stories. Confidential Computing is encryption in use, not a fifth KMS key type.
- Gemini Enterprise Agent Platform is named on this exam guide. Gemini Code Assist and Gemini Cloud Assist are names from a different professional outline.
- Artifact Analysis scans. Binary Authorization gates. Security Health Analytics finds misconfigurations. Cloud IDS inspects traffic.
- Access Transparency logs Google staff. Access Approval gates Google staff. Assured Workloads applies the control package that may require both.
- Professional Cloud Architect case studies are not this exam. Professional Cloud DevOps Engineer pipelines are not this exam. Professional Data Engineer warehouses are not this exam. Professional Security Operations Engineer detection rules are not this exam. Associate Cloud Engineer operator clicks are the floor, not the sitting.
If deleting the scenario still lets you pick the answer from the service name, the question is easier than the live exam.
How this maps to CloudFluently
Start with the official material. The Professional Cloud Security Engineer certification page carries the audience profile, the 2 hour timer, the 50 to 60 question format, the 200 USD fee, and the recommended experience. The Professional Cloud Security Engineer exam guide carries the five sections and the product names. Exam Terms and Conditions explain what it means to pass an Exam, how long a Professional Certification lasts, and the 14 day, 60 day, and 365 day retake waits.
Professional Cloud Security Engineer sits on top of Google Cloud vocabulary and Google Cloud operations, and that ground is already live here. Shared responsibility, product families, and the idea of a cloud bill are the Cloud Digital Leader study notes. Projects, IAM, Compute Engine, Cloud Storage, VPC networks, and the operator form of Cloud Monitoring and Cloud Logging are the Associate Cloud Engineer study notes. The Associate Cloud Engineer exam guide is the operator companion.
The architect reading of a key or a perimeter, when the stem is still a solution recommendation rather than a security control, is the Professional Cloud Architect exam guide. The delivery reading of Binary Authorization, when the stem is a promotion sequence rather than a deploy-time gate, is the Professional Cloud DevOps Engineer exam guide. The warehouse reading of Sensitive Data Protection, when the stem is a pipeline or a reservation rather than a redaction job, is the Professional Data Engineer exam guide.
Work those until the vocabulary, the operator controls, and the neighboring professional habits are automatic, then use this page and the official exam guide for the security-only skills: the identity, the perimeter, the key, and the finding that holds them.
What is the passing score for Professional Cloud Security Engineer? Google does not publish a numeric passing score on the certification page or the exam guide. Exam Terms and Conditions say that if you pass an Exam, you receive a digital certificate after Google has validated your score.
How long is the exam and how many questions are there? The standard sitting is 2 hours with 50 to 60 multiple choice and multiple select questions.
Does this exam use case studies? The certification page and the official exam guide do not publish case studies for this sitting. Study the five sections and the named products.
Is there a prerequisite? No. Google recommends 3 or more years of industry experience, including more than 1 year designing and managing solutions using Google Cloud.
How long does the certification last? A Professional Certification is valid for two years from the date of issue. Renewal is the applicable Exam during the professional eligibility window, which the terms page starts 60 days before expiration. Passing that Exam extends validity for two years from the date of passing.
Can I retake it if I fail? Associate and Professional exams allow four attempts in two years. The waits are 14 days after the first fail, 60 days after the second, and 365 days after the third. Each attempt is paid.
What changed on the current outline? The current guide already names Workforce Identity Federation, Privileged Access Manager, Cloud NGFW, Sensitive Data Protection, Cloud EKM, Confidential Computing, Gemini Enterprise Agent Platform, Binary Authorization, Security Health Analytics, and Assured Workloads. The certifications hub points at Google Cloud Next '26 product updates. The product names that matter are the names on the current exam guide.
Which section is heaviest? Configuring access is about 25%. Ensuring data protection is about 23%. Securing communications and establishing boundary protection is about 22%. Managing operations is about 19%. Supporting compliance requirements is about 11%.
Does Google publish a 700 or 70 percent pass mark? No. That figure is not on the certification page, the exam guide, or the terms page opened for this guide.
How does this exam relate to Associate Cloud Engineer, Professional Cloud Architect, and Professional Cloud DevOps Engineer? Cloud Digital Leader scores vocabulary. Associate Cloud Engineer scores the operator controls. Professional Cloud Architect scores the solution recommendation. Professional Cloud DevOps Engineer scores the pipeline stage. Professional Data Engineer scores the data platform. Professional Cloud Security Engineer scores the identity, the perimeter, the key, and the finding. The official outline is the Professional Cloud Security Engineer exam guide. Use Google for the task statements. Use this page for how those statements get picked, what the current names are, and how to sequence the blueprint.
