🃏 Security Engineer Flashcards

Test your GCP security knowledge.

About This Flashcard Deck

This flashcard deck contains 10 cards covering key Security Engineer concepts for the PCSE exam. Test your GCP security knowledge. Use active recall by attempting to answer each question before revealing the answer.

Card 1 of 10

Question

What is Cloud Armor?

Click to reveal answer

Answer

WAF and DDoS protection service. Applied at the HTTP(S) load balancer. Supports preconfigured rules, custom rules, and rate limiting.

Click to flip back

All Security Engineer Flashcards

1

Q: What is Cloud Armor?

A: WAF and DDoS protection service. Applied at the HTTP(S) load balancer. Supports preconfigured rules, custom rules, and rate limiting.

2

Q: What is VPC Service Controls?

A: Creates a security perimeter around Google Cloud APIs. Prevents data exfiltration even by authorized users.

3

Q: What is the difference between CMEK and CSEK?

A: CMEK: you manage keys in Cloud KMS. CSEK: you supply the encryption key with each API call. CMEK is more practical.

4

Q: What is Cloud DLP?

A: Data Loss Prevention — discovers, classifies, and de-identifies sensitive data (PII, credit cards, SSN) across GCP and SaaS apps.

5

Q: What is Security Command Center?

A: Central dashboard for security and risk management. Includes vulnerability scanning, threat detection, and compliance monitoring.

6

Q: What is Assured Workloads?

A: Creates a controlled environment in GCP for specific compliance needs (FedRAMP, ITAR, etc.) with data residency controls.

7

Q: What are Organization Policies?

A: Constraints applied at the org/folder/project level. Examples: restrict VM external IPs, enforce uniform bucket-level access.

8

Q: What is Binary Authorization?

A: Deploy-time security control that ensures only trusted container images are deployed to GKE.

9

Q: What is BeyondCorp Enterprise?

A: Google's zero-trust solution. Access based on identity + device trust + context. No VPN needed.

10

Q: What is Access Transparency?

A: Logs that show when Google staff access your data for support purposes. Provides visibility and audit trail.

GCP Flashcard Study Approach

Google Cloud exams emphasise service selection and architecture decisions. Use these flashcards to build instant recall of GCP service capabilities, then apply that knowledge to scenario-based practice questions. Pay special attention to cards about managed vs. unmanaged services and serverless options — GCP strongly favours managed and serverless architectures in their exam scenarios.

More PCSE Flashcard Decks