Google Professional Cloud Security Engineer Exam Practice Questions (P. 1)
- Full Access (321 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #1
Which two settings must remain disabled to meet these requirements? (Choose two.)
- APublic IPMost Voted
- BIP Forwarding
- CPrivate Google AccessMost Voted
- DStatic routes
- EIAM Network User Role
AC
Reference:
https://cloud.google.com/vpc/docs/configure-private-google-access

Hi! Do you need help with this question ?
- Why isn't the A the right answer?
- Traducir la pregunta al español
Contributor get free access to an augmented ChatGPT 4 trained with the latest IT Questions.
Question #2
- AA rule that allows all outbound connectionsMost Voted
- BA rule that denies all inbound connectionsMost Voted
- CA rule that blocks all inbound port 25 connections
- DA rule that blocks all outbound connections
- EA rule that allows all inbound port 80 connections
AB
Reference:
https://cloud.google.com/vpc/docs/firewalls

Hi! Do you need help with this question ?
- Why isn't the A the right answer?
- Traducir la pregunta al español
Contributor get free access to an augmented ChatGPT 4 trained with the latest IT Questions.
Question #3
How should the customer achieve this using Google Cloud Platform?
- AUse Cloud Source Repositories, and store secrets in Cloud SQL.
- BEncrypt the secrets with a Customer-Managed Encryption Key (CMEK), and store them in Cloud Storage.Most Voted
- CRun the Cloud Data Loss Prevention API to scan the secrets, and store them in Cloud SQL.
- DDeploy the SCM to a Compute Engine VM with local SSDs, and enable preemptible VMs.
B


Hi! Do you need help with this question ?
- Why isn't the A the right answer?
- Traducir la pregunta al español
Contributor get free access to an augmented ChatGPT 4 trained with the latest IT Questions.
Question #4
What should your team do to meet these requirements?
- ASet up Cloud Directory Sync to sync groups, and set IAM permissions on the groups.Most Voted
- BSet up SAML 2.0 Single Sign-On (SSO), and assign IAM permissions to the groups.
- CUse the Cloud Identity and Access Management API to create groups and IAM permissions from Active Directory.
- DUse the Admin SDK to create groups and assign IAM permissions from Active Directory.
B
Reference:
https://cloud.google.com/blog/products/identity-security/using-your-existing-identity-management-system-with-google-cloud-platform

Hi! Do you need help with this question ?
- Why isn't the A the right answer?
- Traducir la pregunta al español
Contributor get free access to an augmented ChatGPT 4 trained with the latest IT Questions.
Question #5
- AEnsure that the app does not run as PID 1.
- BPackage a single app as a container.Most Voted
- CRemove any unnecessary tools not needed by the app.Most Voted
- DUse public container images as a base image for the app.
- EUse many container image layers to hide sensitive information.
BC
Reference:
https://cloud.google.com/solutions/best-practices-for-building-containers

Hi! Do you need help with this question ?
- Why isn't the A the right answer?
- Traducir la pregunta al español
Contributor get free access to an augmented ChatGPT 4 trained with the latest IT Questions.
Question #6
Which product should be used to meet these requirements?
- ACloud ArmorMost Voted
- BVPC Firewall Rules
- CCloud Identity and Access Management
- DCloud CDN
A
Reference:
https://cloud.google.com/blog/products/identity-security/understanding-google-cloud-armors-new-waf-capabilities

Hi! Do you need help with this question ?
- Why isn't the A the right answer?
- Traducir la pregunta al español
Contributor get free access to an augmented ChatGPT 4 trained with the latest IT Questions.
Question #7
Which two approaches can you take to meet the requirements? (Choose two.)
- AConfigure the project with Cloud VPN.Most Voted
- BConfigure the project with Shared VPC.
- CConfigure the project with Cloud Interconnect.Most Voted
- DConfigure the project with VPC peering.
- EConfigure all Compute Engine instances with Private Access.
AC


Hi! Do you need help with this question ?
- Why isn't the A the right answer?
- Traducir la pregunta al español
Contributor get free access to an augmented ChatGPT 4 trained with the latest IT Questions.
Question #8
ERP systems only accept traffic from Cloud Identity-Aware Proxy.
What should the customer do to meet these requirements?
- AMake sure that the ERP system can validate the JWT assertion in the HTTP requests.Most Voted
- BMake sure that the ERP system can validate the identity headers in the HTTP requests.
- CMake sure that the ERP system can validate the x-forwarded-for headers in the HTTP requests.
- DMake sure that the ERP system can validate the user's unique identifier headers in the HTTP requests.
A


Hi! Do you need help with this question ?
- Why isn't the A the right answer?
- Traducir la pregunta al español
Contributor get free access to an augmented ChatGPT 4 trained with the latest IT Questions.
Question #9
What should you do?
- ACreate an Alerting Policy in Stackdriver using a Process Health condition, checking that the number of executions of the script remains below the desired threshold. Enable notifications.Most Voted
- BCreate an Alerting Policy in Stackdriver using the CPU usage metric. Set the threshold to 80% to be notified when the CPU usage goes above this 80%.
- CLog every execution of the script to Stackdriver Logging. Create a User-defined metric in Stackdriver Logging on the logs, and create a Stackdriver Dashboard displaying the metric.
- DLog every execution of the script to Stackdriver Logging. Configure BigQuery as a log sink, and create a BigQuery scheduled query to count the number of executions in a specific timeframe.
C
Reference:
https://cloud.google.com/logging/docs/logs-based-metrics/

Hi! Do you need help with this question ?
- Why isn't the A the right answer?
- Traducir la pregunta al español
Contributor get free access to an augmented ChatGPT 4 trained with the latest IT Questions.
Question #10
Which logging export strategy should you use to meet the requirements?
- A1. Export logs to a Cloud Pub/Sub topic with folders/NONPROD parent and includeChildren property set to True in a dedicated SIEM project. 2. Subscribe SIEM to the topic.Most Voted
- B1. Create a Cloud Storage sink with billingAccounts/ABC-BILLING parent and includeChildren property set to False in a dedicated SIEM project. 2. Process Cloud Storage objects in SIEM.
- C1. Export logs in each dev project to a Cloud Pub/Sub topic in a dedicated SIEM project. 2. Subscribe SIEM to the topic.
- D1. Create a Cloud Storage sink with a publicly shared Cloud Storage bucket in each project. 2. Process Cloud Storage objects in SIEM.
B


Hi! Do you need help with this question ?
- Why isn't the A the right answer?
- Traducir la pregunta al español
Contributor get free access to an augmented ChatGPT 4 trained with the latest IT Questions.
All Pages