Google Cloud Exam Syllabus

Professional Cloud Security Engineer syllabus, skills measured, and exam topics

A Cloud Security Engineer allows organizations to design and implement secure workloads and infrastructure on Google Cloud. Through an understanding of security best practices and industry requirements, this individual designs, develops, and manages a secure solution by

Skills measured by domain

Use the weighting table to decide where to spend the most study time.

Domain Weight
Section 1: Configuring access 25%
Section 2: Securing communications and establishing boundary protection 22%
Section 3: Ensuring data protection 23%
Section 4: Managing operations 19%
Section 5: Supporting compliance requirements 11%

Detailed outline

Scan each section as a working study checklist instead of one long wall of text.

Section 1: Configuring access (~25% of the exam)

  • 1.1 Managing Cloud Identity. Considerations include:
  • Configuring Google Cloud Directory Sync and implement single sign-on (SSO) with a
  • third-party identity provider.
  • Managing a super administrator account.
  • Automating the user lifecycle management process.
  • Administering user accounts and groups programmatically.
  • Configuring Workforce Identity Federation
  • 1.2 Managing service accounts. Considerations include:
  • Securing and protecting service accounts (including default service accounts).
  • Identifying scenarios requiring service accounts.
  • Creating, disabling, and authorizing service accounts.
  • Securing, auditing, and mitigating the usage of service account keys.

Section 2: Securing communications and establishing boundary protection (~22% of

  • the exam)
  • 2.1 Designing and configuring perimeter security. Considerations include:
  • Configuring network perimeter controls (e.g., Cloud Next Generation Firewall [Cloud
  • NGFW] rules and policies, Identity-Aware Proxy [IAP], load balancers, and Certificate
  • Authority Service).
  • Setting up application layer inspection on Cloud NGFW (e.g., layer 7).
  • Differentiating between private and public IP addressing.
  • Configuring web application firewalls (e.g., Google Cloud Armor).
  • Deploying Secure Web Proxy.
  • Configuring Cloud DNS security settings.
  • Continually monitoring and restricting configured APIs.
  • 2.2 Configuring boundary segmentation. Considerations include:

Section 3: Ensuring data protection (~23% of the exam)

  • 3.1 Protecting sensitive data and preventing data loss. Considerations include:
  • Configuring Sensitive Data Protection (SDP) (e.g., discovering and redacting personally
  • identifiable information (PII), configuring pseudonymization and format preserving
  • encryption).
  • Restricting access to Google Cloud data services (e.g., BigQuery, Cloud Storage, and
  • Cloud SQL datastores).
  • Securing secrets with Secret Manager.
  • Protecting and managing compute instance metadata.
  • 3.2 Managing encryption at rest, in transit, and in use. Considerations include:
  • Identifying use cases for Google default encryption, customer-managed encryption
  • keys (CMEK), and Cloud External Key Manager (EKM).
  • Determining when to use software and hardware keys

Section 4: Managing operations (~19% of the exam)

  • 4.1 Automating infrastructure and application security. Considerations include:
  • Automating security scanning for Common Vulnerabilities and Exposures (CVEs)
  • through a continuous integration and delivery (CI/CD) pipeline.
  • Configuring Binary Authorization to secure GKE clusters or Cloud Run.
  • Automating virtual machine and container image creation (e.g., hardening,
  • maintenance, VM patch management).
  • Managing policy and drift detection at scale (e.g., cloud security posture management,
  • custom organization policies and custom modules for Security Health Analytics).
  • 4.2 Configuring logging, monitoring, and detection. Considerations include:
  • Configuring and analyzing network logs (Cloud Next Generation Firewall [Cloud
  • NGFW], VPC flow logs, Packet Mirroring, Cloud Intrusion Detection System [Cloud IDS],
  • Log Analytics).

Section 5: Supporting compliance requirements (~11% of the exam)

  • 5.1 Adhering to regulatory and industry standards requirements for the cloud. Considerations
  • include:
  • Determining technical needs relative to compute, data, network, and storage.
  • Evaluating the shared responsibility model.
  • Configuring security controls within cloud environments to support compliance
  • requirements (e.g., Assured Workloads, organizational policies, Access Transparency,
  • Access Approval, regionalization of data and services).
  • Determining the Google Cloud environment in scope for regulatory compliance.
  • Mapping compliance requirements to Google Cloud services and security controls (e.g.,
  • network and access segmentation, audit log coverage).