← All Certifications
Google Cloud

Google Cloud Security Engineer Certification

PSE · 6 domains

Last updated: March 31, 2026

Exam Syllabus & Domains

The Google Cloud Security Engineer certification exam covers the following domains. Focus your training time proportionally to each domain's weight.

Domain 1 ~25%

Configuring Access

  • 1.1 Manage Cloud Identity and IAM
  • 1.2 Implement resource hierarchy and organization policies
  • 1.3 Manage service accounts and workload identity
  • 1.4 Configure authentication mechanisms
  • 1.5 Manage and implement authorization controls
IAM Roles (Primitive, Predefined, Custom)IAM Conditions and TagsCloud Identity and Directory SyncWorkforce Identity Federation (SAML/OIDC)Workload Identity FederationService Account Key ManagementOrganization Policy ConstraintsResource Manager HierarchyBeyondCorp Zero-Trust ModelAccess Context Manager
Domain 2 ~20%

Managing Operations

  • 2.1 Configure Cloud Audit Logging
  • 2.2 Manage security monitoring and incident response
  • 2.3 Design and implement logging and monitoring solutions
  • 2.4 Configure log exports and aggregation
Cloud Audit Logs (Admin Activity, Data Access, System Events)Security Command Center (Standard/Premium)Chronicle SIEM and SOAREvent Threat DetectionCloud Logging Sinks and ExportsLog-Based Metrics and AlertsForseti Security (Open Source)Web Security ScannerSecurity Health AnalyticsContainer Threat Detection
Domain 3 ~20%

Configuring Network Security

  • 3.1 Design and configure VPC network security
  • 3.2 Configure network security controls
  • 3.3 Configure perimeter security
  • 3.4 Implement private connectivity
VPC Firewall Rules and PoliciesHierarchical Firewall PoliciesVPC Service Controls PerimetersPrivate Google Access and Private Service ConnectCloud NAT ConfigurationCloud Armor WAF PoliciesIdentity-Aware Proxy (IAP)SSL/TLS Policies for Load BalancersPacket Mirroring for ForensicsCloud IDS (Intrusion Detection)
Domain 4 ~15%

Ensuring Compliance

  • 4.1 Design for regulatory compliance
  • 4.2 Implement organization-level security policies
  • 4.3 Configure data governance controls
Assured Workloads for ComplianceOrganization Policy ServiceData Residency and SovereigntyAccess Transparency LogsAccess Approval WorkflowCompliance Reports ManagerHIPAA, PCI DSS, SOC2 on GCPData Classification and LabelingRetention Policies and Legal Holds
Domain 5 ~20%

Securing Data

  • 5.1 Implement encryption strategies
  • 5.2 Manage secrets and credentials
  • 5.3 Protect sensitive data
  • 5.4 Implement key management
Cloud KMS (Symmetric/Asymmetric Keys)CMEK (Customer-Managed Encryption Keys)CSEK (Customer-Supplied Encryption Keys)Cloud HSM (Hardware Security Module)Secret Manager Versioning and RotationDLP API De-identification TechniquesConfidential Computing and Confidential VMsCertificate Authority ServiceBinary Authorization for ContainersColumn-Level Encryption in BigQuery

Where to Focus Your Study Time

Domains with higher weight have more exam questions — allocate your study hours accordingly.

D1 Configuring Access
~25%
D2 Managing Operations
~20%
D3 Configuring Network Security
~20%
D4 Ensuring Compliance
~15%
D5 Securing Data
~20%

Study Tips

Free Study Resources

๐Ÿ“‹

Study Roadmap

Week-by-week study plan with free resources

โœ…

Study Tracker

Track objective completion with progress dashboard

๐Ÿ’ฐ

Cost Calculator

Total cost breakdown and ROI analysis

๐Ÿงช

Practice Quiz

Test your knowledge with free practice questions

Practice Quiz

Test your knowledge before the exam with our free practice quiz.

Take the Google Cloud Security Engineer Practice Quiz

Get the Google Cloud Security Engineer Study Planner

Fillable PDF with 12-week schedule, domain trackers, flashcard templates, progress tracking, and quick reference sheets. Available in Standard, ADHD-Friendly, Dark Mode, and 4-Format Bundle.

Get the Study Planner — $5.99

Also available as a 4-Format Bundle for $15.99

CyberFolio

Earned your certs? Show employers.

Build a shareable cybersecurity portfolio that highlights your certifications, projects, and skills — free.

Build Your Portfolio →

Free Training Resources

Use these free tools to support your Google Cloud Security Engineer certification training:

Frequently Asked Questions

What is the Google Cloud Security Engineer certification?

The Google Cloud Security Engineer (PSE) is a professional IT certification that validates your knowledge and skills in the exam domains covered. It is recognized globally by employers and is a valuable credential for career advancement in cybersecurity and IT.

What does the Google Cloud Security Engineer certification syllabus cover?

The Google Cloud Security Engineer exam syllabus covers 6 domains. Each domain is weighted differently, so focus your training on higher-weighted domains first. Review the complete domain breakdown above for objectives and key concepts.

How should I study for Google Cloud Security Engineer?

Create a structured study plan covering all exam domains, use practice tests to identify weak areas, and review key concepts regularly. A fillable study planner can help you organize your training with weekly schedules and progress tracking.

How long does it take to prepare for Google Cloud Security Engineer?

Preparation time varies by experience level. Most candidates spend 8-12 weeks of dedicated training. Using a structured study planner with domain-by-domain breakdown helps ensure you cover all certification objectives efficiently.