Skip to main content
Course

Google Professional Cloud Security Engineer Exam Prep

Design and operate secure workloads across Google Cloud.

Advanced

Level

6

Modules

24

Lessons

6

Graded quizzes

10 hours

Estimated time

What you will be able to do

  • Configure access with IAM, organization policies, and workload identity
  • Design network security: VPC controls, firewalls, and private access
  • Protect data with encryption, KMS, DLP, and secret management
  • Operate security: logging, monitoring, and incident response
  • Manage compliance, governance, and regulatory requirements
  • Pass a timed practice exam against the current exam guide

What is inside

6 modules, 24 lessons. Each module ends in a graded quiz.

  1. 01

    Identity, Resource Hierarchy, and Org Policy

    Covers the Google Professional Cloud Security Engineer domain on configuring access within a cloud solution environment. You will learn how Cloud Identity and Google Workspace supply the principals that Google Cloud consumes, how accounts are provisioned, federated, hardened, and retired, and how the organization, folder, and project hierarchy determines what every policy reaches. The module then works through IAM roles, custom roles, conditions, deny policies, and organization policy constraints so that least privilege and guardrails hold at scale.

    4 lessons · 15 quiz questions

  2. 02

    Service Accounts, Federation, and Context-Aware Access

    Covers the machine and human identity half of the exam domain Configuring access within a cloud solution environment, teaching you to design service account usage without downloadable keys, to federate external workloads and an external workforce into Google Cloud, and to gate access on identity plus device and network context. You will learn the difference between granting roles to a service account and granting rights over a service account, how the Security Token Service exchanges an external credential for a short-lived Google Cloud credential, and how attribute conditions keep a federation provider from trusting the whole internet. The module closes with Identity-Aware Proxy, access levels, and IAM conditions so you can choose the right enforcement point for each access path.

    4 lessons · 15 quiz questions

  3. 03

    Network Security and Boundary Protection

    Covers the Google Professional Cloud Security Engineer domain Securing communications and establishing boundary protection. You learn how VPC design, Private Google Access, and Private Service Connect keep traffic off the public internet, how VPC firewall rules and hierarchical firewall policies combine with Cloud NGFW to enforce segmentation, and how VPC Service Controls draws a data boundary that IAM alone cannot. The module closes at the edge with Cloud Load Balancing, Cloud Armor, DDoS defense, and certificate management.

    4 lessons · 15 quiz questions

  4. 04

    Data Protection and Encryption

    Covers the Google Professional Cloud Security Engineer domain for ensuring data protection, from finding and classifying sensitive data through encrypting, tokenizing, and disposing of it. You will work through Sensitive Data Protection discovery and de-identification, Cloud KMS key models including CMEK, CSEK, Cloud HSM, and Cloud EKM, secrets handling in Secret Manager, and the fine grained controls that protect Cloud Storage, managed databases, and BigQuery. Every lesson is framed the way the exam frames it, by matching a stated requirement to the single control that satisfies it.

    4 lessons · 15 quiz questions

  5. 05

    Security Operations and Incident Response

    Covers the Google Professional Cloud Security Engineer objective for managing operations within a cloud solution environment. You will build hardened images and a patched fleet, protect the build pipeline with provenance and Binary Authorization admission control, and design a logging architecture whose routing, retention, and immutability survive an administrator who wants the evidence gone. The module then moves from signal to action, working Security Command Center findings and Google Security Operations detections through triage, containment, cloud forensics, and a vulnerability management workflow that closes with verification.

    4 lessons · 15 quiz questions

  6. 06

    Compliance, Governance, and Exam Readiness

    Covers Section 5 of the Google Professional Cloud Security Engineer exam, supporting compliance requirements, which is the smallest domain by weight and the one that pulls every other section together. You will map regulatory obligations to Google Cloud controls, apply Assured Workloads, residency constraints, and sovereignty tooling, and build continuous compliance monitoring and an audit evidence pipeline. The module closes with three scenario drills and a full readiness review across all five exam sections.

    4 lessons · 15 quiz questions