Google Professional Cloud Security Engineer Exam Prep
Design and operate secure workloads across Google Cloud.
Tuition
$349
Advanced
Level
6
Modules
24
Lessons
6
Graded quizzes
10 hours
Estimated time
What you will be able to do
- Configure access with IAM, organization policies, and workload identity
- Design network security: VPC controls, firewalls, and private access
- Protect data with encryption, KMS, DLP, and secret management
- Operate security: logging, monitoring, and incident response
- Manage compliance, governance, and regulatory requirements
- Pass a timed practice exam against the current exam guide
What is inside
6 modules, 24 lessons. Each module ends in a graded quiz.
- 01
Identity, Resource Hierarchy, and Org Policy
Covers the Google Professional Cloud Security Engineer domain on configuring access within a cloud solution environment. You will learn how Cloud Identity and Google Workspace supply the principals that Google Cloud consumes, how accounts are provisioned, federated, hardened, and retired, and how the organization, folder, and project hierarchy determines what every policy reaches. The module then works through IAM roles, custom roles, conditions, deny policies, and organization policy constraints so that least privilege and guardrails hold at scale.
4 lessons · 15 quiz questions
- 02
Service Accounts, Federation, and Context-Aware Access
Covers the machine and human identity half of the exam domain Configuring access within a cloud solution environment, teaching you to design service account usage without downloadable keys, to federate external workloads and an external workforce into Google Cloud, and to gate access on identity plus device and network context. You will learn the difference between granting roles to a service account and granting rights over a service account, how the Security Token Service exchanges an external credential for a short-lived Google Cloud credential, and how attribute conditions keep a federation provider from trusting the whole internet. The module closes with Identity-Aware Proxy, access levels, and IAM conditions so you can choose the right enforcement point for each access path.
4 lessons · 15 quiz questions
- 03
Network Security and Boundary Protection
Covers the Google Professional Cloud Security Engineer domain Securing communications and establishing boundary protection. You learn how VPC design, Private Google Access, and Private Service Connect keep traffic off the public internet, how VPC firewall rules and hierarchical firewall policies combine with Cloud NGFW to enforce segmentation, and how VPC Service Controls draws a data boundary that IAM alone cannot. The module closes at the edge with Cloud Load Balancing, Cloud Armor, DDoS defense, and certificate management.
4 lessons · 15 quiz questions
- 04
Data Protection and Encryption
Covers the Google Professional Cloud Security Engineer domain for ensuring data protection, from finding and classifying sensitive data through encrypting, tokenizing, and disposing of it. You will work through Sensitive Data Protection discovery and de-identification, Cloud KMS key models including CMEK, CSEK, Cloud HSM, and Cloud EKM, secrets handling in Secret Manager, and the fine grained controls that protect Cloud Storage, managed databases, and BigQuery. Every lesson is framed the way the exam frames it, by matching a stated requirement to the single control that satisfies it.
4 lessons · 15 quiz questions
- 05
Security Operations and Incident Response
Covers the Google Professional Cloud Security Engineer objective for managing operations within a cloud solution environment. You will build hardened images and a patched fleet, protect the build pipeline with provenance and Binary Authorization admission control, and design a logging architecture whose routing, retention, and immutability survive an administrator who wants the evidence gone. The module then moves from signal to action, working Security Command Center findings and Google Security Operations detections through triage, containment, cloud forensics, and a vulnerability management workflow that closes with verification.
4 lessons · 15 quiz questions
- 06
Compliance, Governance, and Exam Readiness
Covers Section 5 of the Google Professional Cloud Security Engineer exam, supporting compliance requirements, which is the smallest domain by weight and the one that pulls every other section together. You will map regulatory obligations to Google Cloud controls, apply Assured Workloads, residency constraints, and sovereignty tooling, and build continuous compliance monitoring and an audit evidence pipeline. The module closes with three scenario drills and a full readiness review across all five exam sections.
4 lessons · 15 quiz questions