Google Professional Cloud Security
Engineer Exam (AGACNP-C) 2026–2027
| Comprehensive Question Practice Test
with Answers & Rationales| Free Pdf
Access
1. A Google Professional Cloud Security Engineer is primarily responsible
for:
A. Designing, implementing, managing, and monitoring secure Google Cloud environments
B. Developing Android applications
C. Repairing physical servers
D. Managing only Cloud Storage buckets
Correct Answer: A
Rationale: Cloud Security Engineers secure cloud infrastructure, applications, identities,
and data using Google Cloud security services and best practices.
2. Which security principle should guide all access decisions in Google Cloud?
A. Principle of Least Privilege
B. Full Administrative Access
C. Shared Administrator Accounts
,D. Anonymous Access
Correct Answer: A
Rationale: Users should receive only the permissions necessary to perform their job
functions.
3. Which Google Cloud service manages identity and access permissions?
A. Identity and Access Management (IAM)
B. Cloud DNS
C. Cloud Build
D. Cloud Storage
Correct Answer: A
Rationale: IAM controls authentication and authorization for Google Cloud resources.
4. IAM permissions are granted through:
A. Roles
B. Firewall Rules
C. Buckets
D. Snapshots
Correct Answer: A
Rationale: Roles contain collections of permissions assigned to principals.
5. Which IAM role provides unrestricted administrative privileges?
A. Owner
,B. Viewer
C. Browser
D. Security Reviewer
Correct Answer: A
Rationale: The Owner role has full access to project resources, including IAM
management.
6. Which IAM role allows users to view resources without modifying them?
A. Viewer
B. Owner
C. Editor
D. Security Admin
Correct Answer: A
Rationale: Viewer grants read-only access.
7. Which authentication method significantly improves account security?
A. Multi-Factor Authentication (MFA)
B. Shared Passwords
C. Guest Accounts
D. Anonymous Login
Correct Answer: A
Rationale: MFA adds an additional verification factor beyond passwords.
, 8. Service Accounts are primarily used to:
A. Authenticate applications and services
B. Authenticate human users
C. Configure firewalls
D. Manage DNS records
Correct Answer: A
Rationale: Service accounts provide identities for workloads.
9. Which practice reduces the risk of credential compromise?
A. Use short-lived credentials whenever possible
B. Embed service account keys in code
C. Share credentials between developers
D. Disable audit logging
Correct Answer: A
Rationale: Short-lived credentials reduce the exposure window.
10. Which Google Cloud feature allows temporary delegated access without
distributing service account keys?
A. Service Account Impersonation
B. Shared Passwords
C. Cloud DNS
D. Cloud Scheduler
Engineer Exam (AGACNP-C) 2026–2027
| Comprehensive Question Practice Test
with Answers & Rationales| Free Pdf
Access
1. A Google Professional Cloud Security Engineer is primarily responsible
for:
A. Designing, implementing, managing, and monitoring secure Google Cloud environments
B. Developing Android applications
C. Repairing physical servers
D. Managing only Cloud Storage buckets
Correct Answer: A
Rationale: Cloud Security Engineers secure cloud infrastructure, applications, identities,
and data using Google Cloud security services and best practices.
2. Which security principle should guide all access decisions in Google Cloud?
A. Principle of Least Privilege
B. Full Administrative Access
C. Shared Administrator Accounts
,D. Anonymous Access
Correct Answer: A
Rationale: Users should receive only the permissions necessary to perform their job
functions.
3. Which Google Cloud service manages identity and access permissions?
A. Identity and Access Management (IAM)
B. Cloud DNS
C. Cloud Build
D. Cloud Storage
Correct Answer: A
Rationale: IAM controls authentication and authorization for Google Cloud resources.
4. IAM permissions are granted through:
A. Roles
B. Firewall Rules
C. Buckets
D. Snapshots
Correct Answer: A
Rationale: Roles contain collections of permissions assigned to principals.
5. Which IAM role provides unrestricted administrative privileges?
A. Owner
,B. Viewer
C. Browser
D. Security Reviewer
Correct Answer: A
Rationale: The Owner role has full access to project resources, including IAM
management.
6. Which IAM role allows users to view resources without modifying them?
A. Viewer
B. Owner
C. Editor
D. Security Admin
Correct Answer: A
Rationale: Viewer grants read-only access.
7. Which authentication method significantly improves account security?
A. Multi-Factor Authentication (MFA)
B. Shared Passwords
C. Guest Accounts
D. Anonymous Login
Correct Answer: A
Rationale: MFA adds an additional verification factor beyond passwords.
, 8. Service Accounts are primarily used to:
A. Authenticate applications and services
B. Authenticate human users
C. Configure firewalls
D. Manage DNS records
Correct Answer: A
Rationale: Service accounts provide identities for workloads.
9. Which practice reduces the risk of credential compromise?
A. Use short-lived credentials whenever possible
B. Embed service account keys in code
C. Share credentials between developers
D. Disable audit logging
Correct Answer: A
Rationale: Short-lived credentials reduce the exposure window.
10. Which Google Cloud feature allows temporary delegated access without
distributing service account keys?
A. Service Account Impersonation
B. Shared Passwords
C. Cloud DNS
D. Cloud Scheduler