GCP Prep
ProfessionalSecurityArchitectCloud Engineer

Professional Cloud Security Engineer

Professional Cloud Security Engineer covers designing and implementing secure infrastructure on Google Cloud: access control, network boundary protection, data protection, security operations and regulatory compliance. It is the deepest identity-focused exam in the programme.

Overview

This exam goes deeper on identity than any other. Not just roles and bindings, but conditional access, workload identity federation, service account impersonation, delegation and the specific risks each one carries.

Organisation policy is the second pillar and the one people most often underestimate. The exam distinguishes carefully between preventative controls that stop something happening and detective controls that tell you it happened — and asks which is appropriate.

Encryption and key management are examined with precision: default encryption, customer-managed keys, customer-supplied keys, key rotation, and the operational consequences of each choice.

Compliance appears as scenarios rather than trivia. You will not be asked to recite a regulation, but you will be asked which control satisfies a stated requirement such as data residency or separation of duties.

Level
Professional
Exam length
120 minutes
Questions
50–60 multiple choice and multiple select
Registration fee
USD $200 (plus tax where applicable)
Valid for
2 years
Delivery
Online proctored, or onsite at a test centre
Recommended experience (official)
Google recommends 3+ years of industry experience, including 1+ year designing and managing solutions on Google Cloud.

Our difficulty rating

4/5

Our recommended preparation

814weeks

Difficulty and preparation time are GCP Prep's own editorial assessments, not official figures.

Who Should Take This Certification?

  • Cloud security engineers and analysts
  • Infrastructure engineers moving into security
  • Architects with security ownership
  • Compliance and governance specialists working with cloud teams

Skills Covered

  • Identity and access management design at organisation scale
  • Organisation policy and preventative guardrails
  • Network boundary protection and service perimeters
  • Encryption, key management and customer-managed keys
  • Data classification, loss prevention and residency
  • Security monitoring, threat detection and incident response
  • Mapping controls to compliance frameworks

Exam Topics

Weightings are shown only where they are officially published — we do not estimate them.

1.Configuring access

~27%
  • Designing IAM across an organisation, including custom roles
  • Service accounts, impersonation, key management and workload identity
  • Conditional access and context-aware policy
  • Federating external identities and single sign-on
  • Separation of duties and privileged access review

2.Securing communications and establishing boundary protection

~21%
  • VPC design, firewall policy and hierarchical firewall rules
  • Service perimeters and controlling data exfiltration paths
  • Private connectivity to managed services
  • Protecting public endpoints against common web attacks
  • TLS, certificate management and secure hybrid connectivity

3.Ensuring data protection

~20%
  • Default encryption, customer-managed and customer-supplied keys
  • Key rotation, destruction and separation of key administration
  • Discovering and classifying sensitive data
  • De-identification, masking and tokenisation
  • Secret management and credential hygiene

4.Managing operations

~18%
  • Centralised security posture monitoring and findings triage
  • Audit logging: admin activity, data access and access transparency
  • Vulnerability management and image hardening
  • Incident detection, investigation and response

5.Supporting compliance requirements

~14%
  • Mapping technical controls to regulatory requirements
  • Data residency and sovereignty controls
  • Evidence collection and continuous compliance monitoring
  • Shared responsibility boundaries in a compliance context

Preparation Roadmap

Our suggested order of study. Tick steps as you complete them — progress is saved in this browser.

Loading your progress…

Progress is saved in this browser

  1. IAM in depth

    Far beyond the Associate level. Policy structure, inheritance, conditions, custom roles and impersonation chains.

  2. Resource hierarchy and organisation policy

    Preventative guardrails: what organisation policy constraints can and cannot stop, and where to apply them.

  3. Network security

    Firewall policy, hierarchical rules, private access to services and service perimeters against exfiltration.

  4. Encryption and key management

    Default encryption, CMEK, CSEK, rotation and the operational trade-offs of managing your own keys.

  5. Data protection and classification

    Discovering sensitive data, de-identification techniques and choosing between masking and tokenisation.

  6. Security operations

    Posture management, findings triage, audit log types and what each one actually records.

  7. Compliance mapping

    Translating a stated regulatory requirement into a specific technical control.

  8. Practice questions and mock exams

    Concentrate on IAM and boundary-protection questions; between them they carry close to half the exam.

Certification ready

Study Resources

Learning-hub topics that cover this certification's material, written by us.

Official documentation and training remain the authoritative source for exam content. Our material explains concepts in our own words and is designed to sit alongside it, not replace it.

Practice Questions & Mock Exam

We have 14 original questions relevant to this certification, each with an explanation of why the correct answer is correct and why every distractor is not.

Career Opportunities

Cloud Security Engineer

Design and operate the security controls for a cloud estate.

Security Architect

Set security direction and standards across an organisation.

Compliance / GRC Engineer

Translate regulatory obligations into enforceable technical controls.

Cloud Infrastructure Engineer (security-focused)

Build and maintain hardened landing zones and platform guardrails.

Explore career resources

Frequently Asked Questions

Do I need a security background?
It helps considerably but is not essential. Strong infrastructure engineers pass this regularly. What you cannot skip is IAM depth — this exam expects far more than the Associate level.
How does it compare to vendor-neutral security certifications?
It is narrower and more implementation-focused. Broad security certifications test principles across the field; this one tests how those principles are implemented on one platform. They complement each other well.
Is Associate Cloud Engineer a good prerequisite?
Yes. It gives you the IAM, networking and resource hierarchy foundation this exam builds on, and it makes the step up much less steep.
How much of it is compliance trivia?
Very little. Compliance appears as scenarios — a requirement is stated and you choose the control that satisfies it. You are not asked to recite regulations.