Other Certifications · GCP PCSE

Google Cloud — Professional Cloud Security Engineer

The Professional Cloud Security Engineer (PCSE) is Google Cloud's own security specialty credential, and with it this course's certification shelf finally covers all three major hyperscalers side by side: AWS Certified Security – Specialty, Microsoft AZ-500, and now GCP. All three test the same underlying job — configure access management, network security, and data protection correctly on one specific cloud — but PCSE gets there through a format the other two don't lean on nearly as hard: multiple-choice and multiple-select questions built around a small set of fictional company case studies that Google publishes in advance, so a chunk of the exam is "apply this to TerramEarth's stated requirements," not "recall this fact in isolation."

☺ Explain it like I'm 10

Some tests just ask you to recite facts — "what's the capital of France." This exam is more like being handed a page about a made-up company before the test even starts — what it sells, what it's worried about, what its old creaky server room looks like — and then being asked "given everything you just read about this company, which fix actually solves their problem without breaking something else they told you they need?" You can't guess your way through that with flashcards. You have to actually understand how the pieces fit together.

🦥🐿️Your hosts for this topic: Sol the Sloth & Nutty the Squirrel — Sol already walks every storage bucket and IAM policy one at a time in Cloud security posture, which is most of what this exam actually grades; Nutty is here because nobody digs up the right fact for the right case study faster than the squirrel who filed it away in the first place.

What the PCSE actually is, and who it's for

☺ Like you're 10: It's Google's answer to "prove you can secure a Google Cloud environment," and it's a knowledge exam you sit at a keyboard, not a live cluster you have to fix.

The Professional Cloud Security Engineer is one of Google Cloud's professional-level certifications, sitting above the associate tier (Associate Cloud Engineer, Cloud Digital Leader) in the same way AWS's Security – Specialty sits above AWS's foundational and associate exams. Unlike the CKA or CKS covered elsewhere on this page — both entirely performance-based, graded on the live state of a real cluster — the PCSE is a knowledge exam: multiple-choice and multiple-select questions delivered in a proctored testing environment, with no terminal, no live GCP project, and nothing to configure by hand during the exam itself. It targets people who design and implement security controls on Google Cloud specifically: engineers responsible for a Google Cloud organization's IAM structure, network perimeter, encryption posture, and the logging and compliance evidence that proves all of it is actually working.

◆ Key idea

Three different layers answer three different questions, and the exam expects you to know which one to reach for: IAM answers "who is allowed to call this API," VPC Service Controls answers "can this data cross this boundary at all, regardless of who's asking," and firewall rules answer "can this packet reach this destination in the first place." A case-study question that describes a data-exfiltration concern is testing whether you reach for VPC-SC — not whether you can recite that IAM roles exist.

Format, cost, and exam-day logistics

☺ Like you're 10: Two hours, a proctor watching over video, and a bill you pay yourself — same shape as most professional certification exams, priced and timed a little differently from Google's other badges.

ItemWhat is generally published
FormatProctored, multiple choice and multiple select — delivered online-proctored from your own machine or in person at a testing center; no live GCP console or terminal task
Duration2 hours
Question countHistorically in the 50–60 question range
Passing scoreNot published as a fixed percentage — Google reports a scaled pass/fail result, not a numeric cut score
Validity2 years from the date you pass, after which recertification requires sitting the current exam again
PriceAround USD $200 — notably below the ~$300 tier AWS charges for its Security – Specialty exam
PrerequisitesNone enforced at registration — Google's own guidance recommends 3+ years of industry experience, including 1+ year designing and managing security solutions on Google Cloud specifically
DeliveryOnline proctoring (a webcam-monitored session at home) or an in-person Kryterion/Webassessor testing center, candidate's choice at booking
Domain weightsUnlike the CNCF's precisely published percentages for the CKA and CKS, Google's own exam guide does not break its five sections into numbered weights at every revision — treat the ordering below as the official guide's own sequence, not a ranking by exam share
⚠ Verify this before you book

Price, question count, the prerequisite guidance, and the exact domain wording all change between exam guide revisions. Nothing on this page is authoritative — this site is independent and unofficial. Confirm current details on the official Google Cloud Professional Cloud Security Engineer page before you register, and read the current exam guide PDF linked from that page — it is the single source Google itself tells candidates to study from.

↗ Google Cloud official PCSE page

The case-study format: why this isn't a pure recall exam

☺ Like you're 10: Before you ever sit the test, Google hands you a stack of "here's a fake company and everything it's worried about" — and you're allowed, expected even, to read it beforehand.

This is the detail the brief for this page calls out specifically, and it's real: several of Google Cloud's professional-level exams, PCSE among them, are built around a small set of published case studies — fictional companies with a stated business situation, an existing technical environment, and explicit business and technical requirements. Google posts these case studies openly on its certification pages before the exam, and a portion of the exam's questions reference one directly: "Given TerramEarth's stated requirement to keep telemetry data within specific regions, which control satisfies that constraint without breaking the analytics pipeline they also described?" You aren't just recalling that a feature exists — you're deciding which feature satisfies a specific, previously-stated constraint without violating another constraint stated two paragraphs earlier in the same case study.

The named case studies rotate and get revised over time, but at last check the shared pool circulated across Google's professional exams included companies like Mountkirk Games (a mobile game studio scaling a backend fast), TerramEarth (heavy-equipment manufacturer with regional data-residency constraints), EHR Healthcare (a healthcare records platform with compliance obligations), and Helicopter Racing League (a media company streaming live telemetry). Treat that list as a snapshot, not a guarantee — confirm which case studies the current exam guide names before you study them, because Google has swapped and retired them before.

This is a genuinely different exam-preparation habit than AWS's or Azure's sibling exams use. AWS Certified Security – Specialty and Microsoft's AZ-500 both include scenario-style questions too, but neither publishes a fixed roster of named case studies for you to read cold before exam day — their scenarios are written fresh, into the exam, and never disclosed in advance. Reading Google's published case studies ahead of time is closer to advance discovery than most professional certification prep gets, and it's free, effective study time most candidates skip.

The five domains, and where each one sits in the hierarchy

☺ Like you're 10: Five topics, and they line up almost exactly with how a Google Cloud organization is actually built — from the top of the org chart down to the actual data.

The official exam guide's five sections read, roughly, as: configuring access, configuring network security, ensuring data protection, managing operations, and supporting compliance requirements. Regrouped by where each one physically attaches to a Google Cloud resource hierarchy — Organization, then Folder, then Project, then the resources living inside it — a cleaner shape falls out than the guide's own flat list suggests, and it's one this course's cloud and infrastructure security material already tracks closely.

Org-wide identity narrows to a perimeter, narrows to the data — operations and compliance watch all three Domain 1 — Configure access Cloud Identity · IAM roles & Conditions · Organization Policy — spans the whole org Domain 2 — Configure network security VPC Service Controls · hierarchical firewalls · Cloud Armor · private connectivity Domain 3 — Ensure data protection Cloud KMS / HSM · CMEK · Sensitive Data Protection (DLP) Domains 4 & 5 — Manage operations · Support compliance requirements Cloud Audit Logs → Security Command Center → Assured Workloads / Access Transparency — watching every layer above, continuously, not just at deploy time

That bottom band is the point worth sitting with: nothing about IAM, VPC-SC, or Cloud KMS being configured correctly on day one guarantees they're still configured correctly on day two hundred. Domains 4 and 5 exist because a security engineer's job doesn't end at "provisioned correctly" — it continues into "still correct, and provably so, next quarter."

Domain by domain: what's actually tested, and where to study it here

☺ Like you're 10: Here's the real substance behind each of those five section titles, in the order Google's own guide lists them.

Configuring access within a cloud solution environment

Covers Cloud Identity setup and its relationship to an organization's existing identity provider, provisioning and managing user and group identities, configuring strong authentication (multi-factor enforcement, Workforce Identity Federation for external users, Workload Identity Federation so a workload authenticates without a long-lived key), and — the largest chunk of it — authorization: predefined versus custom IAM roles, least-privilege role design, and IAM Conditions that scope a binding by time, resource attribute, or request context rather than granting a role unconditionally.

# A time-boxed, conditional IAM binding — access that expires on its own,
# rather than access someone has to remember to revoke later.
gcloud projects add-iam-policy-binding my-project \
  --member="user:alice@example.com" \
  --role="roles/storage.objectViewer" \
  --condition='expression=request.time < timestamp("2026-12-31T00:00:00Z"),title=temp-audit-access,description=expires-end-of-year'

# An Organization Policy constraint enforced at the org node — every project
# under it inherits the restriction unless a folder or project explicitly overrides it.
# organizations/123456789012/policies/compute.vmExternalIpAccess
name: organizations/123456789012/policies/compute.vmExternalIpAccess
spec:
  rules:
    - denyAll: true   # no VM anywhere in this org gets an external IP by default

Study here: Workload Identity & Pipeline IAM covers Workload Identity Federation and the "identity, not a shared secret" pattern this domain expects for service-to-service and CI/CD access. Cloud security posture — Sol's own lesson — covers reviewing IAM bindings and Organization Policy the same methodical, one-resource-at-a-time way a case-study question expects you to reason about them.

Configuring network security

The perimeter layer: designing network segmentation with Shared VPC and hierarchical firewall policies enforced above the project level, establishing VPC Service Controls perimeters that stop data from crossing a defined boundary regardless of IAM permissions, configuring Cloud Armor for edge protection (WAF rules, rate limiting, geo-based blocking) in front of a load balancer, and establishing private connectivity — Private Google Access, Private Service Connect, Cloud VPN, and Interconnect — so traffic to Google APIs and between environments never has to touch the public internet.

# A VPC-SC perimeter around a project holding sensitive data — even a caller
# with valid IAM permissions can't exfiltrate data out of these services
# once the perimeter is enforced, because IAM and VPC-SC answer different questions.
gcloud access-context-manager perimeters create secure_data_perimeter \
  --title="Secure Data Perimeter" \
  --resources=projects/111111111111 \
  --restricted-services=storage.googleapis.com,bigquery.googleapis.com \
  --policy=123456789012

# Cloud Armor: block a single abusive IP range at the edge, before it ever
# reaches the backend service the load balancer fronts.
gcloud compute security-policies rules create 1000 \
  --security-policy=edge-policy \
  --src-ip-ranges="203.0.113.0/24" \
  --action=deny-403

Study here: CNAPP & the Unified Cloud Security Stack covers the posture-management layer that surfaces a misconfigured perimeter or an over-broad firewall rule before an attacker finds it first. For workloads running on GKE specifically, Kubernetes Security Deep Dive carries over almost directly — GKE's own NetworkPolicy and Binary Authorization integration are the case-study answer whenever a scenario names a containerized workload.

Ensuring data protection

Everything about the data itself once it's at rest or in transit: managing encryption with Cloud KMS (software-backed keys), Cloud HSM (hardware-backed), and Cloud EKM (external key management, for organizations that refuse to let Google hold the key material at all); choosing between Google-managed, customer-managed (CMEK), and customer-supplied (CSEK) encryption keys and knowing which case-study requirement forces which choice; key rotation and access control on the keys themselves; and using Sensitive Data Protection (formerly branded the DLP API) to discover, classify, and de-identify sensitive data like PII before it ever leaves a controlled boundary.

# A CMEK key with automatic rotation, applied to a bucket — Google still runs
# the encryption, but the customer controls and can revoke the key.
gcloud kms keys create app-data-key \
  --keyring=app-keyring --location=us-central1 \
  --purpose=encryption --rotation-period=90d --next-rotation-time=2026-11-15T00:00:00Z

gsutil kms encryption \
  -k projects/my-project/locations/us-central1/keyRings/app-keyring/cryptoKeys/app-data-key \
  gs://my-sensitive-bucket

Study here: Cryptography & Key Management covers the CMEK-versus-CSEK-versus-external-KMS decision this domain tests directly, plus key rotation and revocation as an operational habit rather than a one-time setup step. Secrets management — Ellie's own lesson — covers the adjacent discipline of never letting the key that unlocks the data sit somewhere it could be found either.

Managing operations within a cloud solution environment

Building and deploying infrastructure securely (Binary Authorization gating what container images GKE is even allowed to run, Artifact Registry vulnerability scanning before an image ships), analyzing Cloud Audit Logs — Admin Activity, Data Access, and System Event logs each capture something different, and a case-study question testing "who accessed this data" is testing whether you know Data Access logs are the ones that answer it — and deploying detective, preventive, and corrective controls through Security Command Center, Google Cloud's built-in posture and threat-findings surface.

# A Binary Authorization policy: GKE refuses to run any image that isn't
# attested by a named authority — an unsigned or unscanned image never starts.
defaultAdmissionRule:
  evaluationMode: REQUIRE_ATTESTATION
  enforcementMode: ENFORCED_BLOCK_AND_AUDIT_LOG
  requireAttestationsBy:
    - projects/my-project/attestors/vuln-scan-attestor

Study here: Detection Engineering & Security Observability is the direct technical core of this domain — turning raw audit-log volume into findings someone actually acts on is exactly what Security Command Center and its case-study scenarios are testing. Software Bills of Materials covers the provenance half of what an attestor is actually vouching for before Binary Authorization lets an image run.

Supporting compliance requirements

The last domain is where a case study's regulatory language turns into a specific product choice: evaluating compliance posture against a named framework, using Assured Workloads to enforce data-residency and personnel-access constraints for regulated workloads (a case study naming a specific region or a specific compliance regime is often pointing straight at this control), and using Access Transparency and Access Approval so an organization can see, and in some cases explicitly approve, when Google personnel access its data for support purposes.

Study here: Compliance as Code at Scale covers turning a named framework's requirements into an automatically-checked control rather than a point-in-time audit exercise, which is the same shift this domain expects on Google Cloud specifically. Compliance & governance — Nutty's own lesson — covers the broader discipline of having evidence ready before an auditor, or an exam question, ever asks for it.

🦥 Sol's workshop · 40 min

On a free-tier GCP project: create a folder with an Organization Policy constraint denying external IPs on Compute instances, put a VPC Service Controls perimeter around one project holding a Cloud Storage bucket, encrypt that bucket with a CMEK key you create yourself, and then open Security Command Center and read the findings it already generated about the project before you touched anything. Four domains, one small project, about forty minutes — slow and methodical, exactly the way Sol reviews a bucket, beats a weekend of flashcards for this exam specifically.

How the PCSE completes the three-major-cloud security set

☺ Like you're 10: Same job — lock down a cloud account properly — asked three different ways by three different companies.

Read the AWS Security – Specialty and AZ-500 pages alongside this one and the shape becomes clear: all three exams test the same underlying competencies — identity and access, network boundary controls, data-at-rest and in-transit protection, detection and logging, and compliance evidence — mapped onto three different product surfaces and three different exam philosophies.

AWS Security – SpecialtyAzure AZ-500GCP PCSE
FormatMultiple choice / multiple responseMultiple choice, drag-drop, and scenario case studiesMultiple choice / multiple select
Scenario styleFresh scenarios written into the exam, never disclosed beforehandCase-study sections within the exam itself, not pre-publishedReferences a small set of company case studies published openly in advance
Domain weightsPublished as explicit percentages per domainPublished as a percentage range per functional groupHistorically not broken into numeric percentages in the guide
Signature control surfaceIAM policies, GuardDuty, KMS, Security HubEntra ID (Conditional Access), Defender for Cloud, Key VaultIAM Conditions, VPC Service Controls, Cloud KMS, Security Command Center
Where to study it hereAWS Certified Security – SpecialtyMicrosoft AZ-500This page

Verify every cell of that table on the vendor's own current page before you plan around it — exam formats, and especially whether a given vendor has quietly added a hands-on lab component, are exactly the kind of detail certification bodies change without much notice. The full comparison, including where each of these sits next to the Certified DevSecOps Professional and the Kubernetes-specific credentials, lives on the certifications hub.

Who should take it, and who should look elsewhere first

☺ Like you're 10: Right test for someone whose actual job is already "keep our Google Cloud org locked down" — wrong test for someone who's never opened the GCP console.

The right candidate is a security or platform engineer who already works inside a Google Cloud organization and owns, or is being asked to own, its IAM structure, network perimeter, and encryption posture — someone for whom "does this satisfy TerramEarth's stated residency requirement" is a recognizable shape of question because they answer versions of it at work already. It's also a reasonable next step for someone who has already cleared the CKA or the CKS and whose organization now runs primarily on GKE — the Kubernetes fluency carries over directly into the network-security and operations domains here.

Look elsewhere first if any of these fit. Your organization runs primarily on AWS or Azure — the product-specific knowledge this exam tests (VPC-SC, Cloud Armor, Assured Workloads) simply won't be what you use day to day; take the AWS exam or AZ-500 instead, whichever matches your actual environment. You want hands-on, performance-graded validation — this exam never asks you to touch a live console, so if what you actually want to prove is that you can configure something correctly under time pressure, the CKS tests that instinct far more directly, just on Kubernetes rather than on a specific cloud's IAM surface. You're new to Google Cloud entirely — start with the Associate Cloud Engineer exam or simply spend a few weeks in a free-tier project first; PCSE assumes GCP fluency, not GCP literacy.

🎬 At the Shift-Left Squad
🐿️

Nutty the Squirrel: Found it — the current PCSE case studies are posted right on Google's certification page. I've filed away notes on all four.

🦊

Foxy: Wait, they just publish the exam scenarios ahead of time? Doesn't that make it easier?

🦥

Sol the Sloth: Easier to know the company. Not easier to know which control satisfies which requirement without breaking a different requirement stated two lines later. That part still takes actually understanding it.

🐘

Ellie the Elephant: TerramEarth's case study mentions regional data residency. That's an Assured Workloads question wearing an encryption costume — don't reach for Cloud KMS first and stop there.

🐢

Timmy the Turtle: And none of this is graded on whether you actually configured it. It's still multiple choice under the hood.

🐿️

Nutty the Squirrel: Which is exactly why I keep the notes. Recall the right shelf, and the right answer is already sitting on it.

🦥 Sol's checkpoint

1. How does the PCSE's exam format differ from the CKA and CKS covered elsewhere on this site? 2. What is a "case study" on this exam, and how is Google's use of them different from how AWS and Azure write their own scenario questions? 3. Give one example of a requirement that IAM alone cannot satisfy, and name the Google Cloud control that does. 4. Which of the five domains covers Cloud Audit Logs and Security Command Center? 5. Name two situations in which someone should take the AWS or Azure security exam instead of the PCSE.

Check your answers
  1. The PCSE is a knowledge exam — multiple choice and multiple select, no live environment — while the CKA and CKS are entirely performance-based, graded on the end state of a real cluster you actually configure during the exam.
  2. A case study is a fictional company Google publishes in advance with a stated business situation, existing environment, and explicit requirements; a portion of exam questions ask you to apply a control to that specific, previously-read scenario. AWS and Azure both use scenario-style questions too, but neither publishes a fixed, named roster of case studies for candidates to study before exam day the way Google does.
  3. A requirement to stop data from crossing a boundary regardless of who's asking — for example, preventing a Cloud Storage bucket's contents from ever being copied to a project outside a defined perimeter, even by a caller with valid IAM permissions. VPC Service Controls is the control that satisfies it; IAM only governs who can call an API, not whether the data itself is allowed to leave a boundary.
  4. "Managing operations within a cloud solution environment" — it covers analyzing Cloud Audit Logs and deploying detective, preventive, and corrective controls through Security Command Center.
  5. Any two of: the organization runs primarily on AWS or Azure rather than Google Cloud; the candidate wants hands-on, performance-graded validation rather than a knowledge exam; the candidate is new to the relevant cloud platform and should build fluency there first before attempting a specialty-level credential.