Google Professional-Cloud-Security-Engineer Daily Practice Exam New 2022 Updated 136 Questions [Q15-Q37]

Share

Google Professional-Cloud-Security-Engineer Daily Practice Exam New 2022 Updated 136 Questions

Use Valid Professional-Cloud-Security-Engineer Exam - Actual Exam Question & Answer


Google Professional Cloud Security Engineer Exam advantages

  • Also the GCP security engineer has exceptional knowledge of GCP and cloud architecture. In this way, they make sure to plan, organize, develop and manage scalable, dynamic and highly accessible solutions to the company's objectives.

  • Plus, they gain real-world knowledge through many hands-on lab projects. It goes without saying that a GCP certified professional security engineer is ready to go and earning a good salary.

  • The candidate will have the opportunity to assign components of the solution, including infrastructure elements such as networks, systems and application services.


Google Professional Cloud Security Engineer Exam Cover Topics

Candidates must know the exam topics before they start of preparation. Because it will really help them in hitting the core. Our Google Professional Cloud Security Engineer exam dumps will include the following topics:

  • Management of operations in a cloud solution environment
  • Ensuring data protection
  • Configuring access within a cloud solution environment
  • Ensuring compliance
  • Configuring network security

 

NEW QUESTION 15
A company is running workloads in a dedicated server room. They must only be accessed from within the private company network. You need to connect to these workloads from Compute Engine instances within a Google Cloud Platform project.
Which two approaches can you take to meet the requirements? (Choose two.)

  • A. Configure the project with Cloud Interconnect.
  • B. Configure the project with Shared VPC.
  • C. Configure the project with VPC peering.
  • D. Configure the project with Cloud VPN.
  • E. Configure all Compute Engine instances with Private Access.

Answer: C,E

Explanation:
Explanation/Reference: https://cloud.google.com/solutions/secure-data-workloads-use-cases

 

NEW QUESTION 16
You are a member of the security team at an organization. Your team has a single GCP project with credit card payment processing systems alongside web applications and data processing systems. You want to reduce the scope of systems subject to PCI audit standards.
What should you do?

  • A. Use only applications certified compliant with PA-DSS.
  • B. Use VPN for all connections between your office and cloud environments.
  • C. Use multi-factor authentication for admin access to the web application.
  • D. Move the cardholder data environment into a separate GCP project.

Answer: B

 

NEW QUESTION 17
You are part of a security team that wants to ensure that a Cloud Storage bucket in Project A can only be readable from Project B.
You also want to ensure that data in the Cloud Storage bucket cannot be accessed from or copied to Cloud Storage buckets outside the network, even if the user has the correct credentials.
What should you do?

  • A. Enable Private Access in Project A and B networks with strict firewall rules to allow communication between the networks.
  • B. Enable VPC Service Controls, create a perimeter with Project A and B, and include Cloud Storage service.
  • C. Enable VPC Peering between Project A and B networks with strict firewall rules to allow communication between the networks.
  • D. Enable Domain Restricted Sharing Organization Policy and Bucket Policy Only on the Cloud Storage bucket.

Answer: D

Explanation:
https://cloud.google.com/resource-manager/docs/organization-policy/restricting-domains

 

NEW QUESTION 18
A company allows every employee to use Google Cloud Platform. Each department has a Google Group, with all department members as group members. If a department member creates a new project, all members of that department should automatically have read-only access to all new project resources. Members of any other department should not have access to the project. You need to configure this behavior.
What should you do to meet these requirements?

  • A. Create a Folder per department under the Organization. For each department's Folder, assign the Project Browser role to the Google Group related to that department.
  • B. Create a Project per department under the Organization. For each department's Project, assign the Project Viewer role to the Google Group related to that department.
  • C. Create a Folder per department under the Organization. For each department's Folder, assign the Project Viewer role to the Google Group related to that department.
  • D. Create a Project per department under the Organization. For each department's Project, assign the Project Browser role to the Google Group related to that department.

Answer: C

 

NEW QUESTION 19
Your team sets up a Shared VPC Network where project co-vpc-prod is the host project. Your team has configured the firewall rules, subnets, and VPN gateway on the host project. They need to enable Engineering Group A to attach a Compute Engine instance to only the 10.1.1.0/24 subnet.
What should your team grant to Engineering Group A to meet this requirement?

  • A. Compute Shared VPC Admin Role at the service project level.
  • B. Compute Network User Role at the host project level.
  • C. Compute Network User Role at the subnet level.
  • D. Compute Shared VPC Admin Role at the host project level.

Answer: D

Explanation:
Reference:
https://cloud.google.com/vpc/docs/shared-vpc

 

NEW QUESTION 20
Which two security characteristics are related to the use of VPC peering to connect two VPC networks? (Choose two.)

  • A. Ability to share specific subnets across peered networks
  • B. Firewall rules that can be created with a tag from one peered network to another peered network
  • C. Ability to peer networks that belong to different Google Cloud Platform organizations
  • D. Central management of routes, firewalls, and VPNs for peered networks
  • E. Non-transitive peered networks; where only directly peered networks can communicate

Answer: B,D

 

NEW QUESTION 21
You want to evaluate GCP for PCI compliance. You need to identify Google's inherent controls.
Which document should you review to find the information?

  • A. PCI DSS Requirements and Security Assessment Procedures
  • B. Google Cloud Platform: Customer Responsibility Matrix
  • C. Product documentation for Compute Engine
  • D. PCI SSC Cloud Computing Guidelines

Answer: D

 

NEW QUESTION 22
You are responsible for protecting highly sensitive data in BigQuery. Your operations teams need access to this data, but given privacy regulations, you want to ensure that they cannot read the sensitive fields such as email addresses and first names. These specific sensitive fields should only be available on a need-to-know basis to the HR team. What should you do?

  • A. Perform data redaction with the DLP API and store that data in BigQuery for later use.
  • B. Perform data inspection with the DLP API and store that data in BigQuery for later use.
  • C. Perform data masking with the DLP API and store that data in BigQuery for later use.
  • D. Perform tokenization for Pseudonymization with the DLP API and store that data in BigQuery for later use.

Answer: B

 

NEW QUESTION 23
You are part of a security team that wants to ensure that a Cloud Storage bucket in Project A can only be readable from Project B.
You also want to ensure that data in the Cloud Storage bucket cannot be accessed from or copied to Cloud Storage buckets outside the network, even if the user has the correct credentials.
What should you do?

  • A. Enable Private Access in Project A and B networks with strict firewall rules to allow communication between the networks.
  • B. Enable VPC Service Controls, create a perimeter with Project A and B, and include Cloud Storage service.
  • C. Enable VPC Peering between Project A and B networks with strict firewall rules to allow communication between the networks.
  • D. Enable Domain Restricted Sharing Organization Policy and Bucket Policy Only on the Cloud Storage bucket.

Answer: D

 

NEW QUESTION 24
An organization's typical network and security review consists of analyzing application transit routes, request handling, and firewall rules. They want to enable their developer teams to deploy new applications without the overhead of this full review.
How should you advise this organization?

  • A. All production applications will run on-premises. Allow developers free rein in GCP as their dev and QA platforms.
  • B. Use Forseti with Firewall filters to catch any unwanted configurations in production.
  • C. Mandate use of infrastructure as code and provide static analysis in the CI/CD pipelines to enforce policies.
  • D. Route all VPC traffic through customer-managed routers to detect malicious patterns in production.

Answer: C

Explanation:
Explanation

 

NEW QUESTION 25
Your company requires the security and network engineering teams to identify all network anomalies within and across VPCs, internal traffic from VMs to VMs, traffic between end locations on the internet and VMs, and traffic between VMs to Google Cloud services in production. Which method should you use?

  • A. Define an organization policy constraint.
  • B. Configure packet mirroring policies.
  • C. Enable VPC Flow Logs on the subnet.
  • D. Monitor and analyze Cloud Audit Logs.

Answer: C

 

NEW QUESTION 26
Applications often require access to "secrets" - small pieces of sensitive data at build or run time. The administrator managing these secrets on GCP wants to keep a track of "who did what, where, and when?" within their GCP projects.
Which two log streams would provide the information that the administrator is looking for? (Choose two.)

  • A. VPC Flow logs
  • B. Data Access logs
  • C. Admin Activity logs
  • D. Agent logs
  • E. System Event logs

Answer: B,C

Explanation:
Explanation/Reference: https://cloud.google.com/kms/docs/secret-management

 

NEW QUESTION 27
An engineering team is launching a web application that will be public on the internet. The web application is hosted in multiple GCP regions and will be directed to the respective backend based on the URL request.
Your team wants to avoid exposing the application directly on the internet and wants to deny traffic from a specific list of malicious IP addresses Which solution should your team implement to meet these requirements?

  • A. NAT Gateway
  • B. Cloud Armor
  • C. SSL Proxy Load Balancing
  • D. Network Load Balancing

Answer: B

 

NEW QUESTION 28
An organization is working on their GDPR compliance strategy. It wants to ensure that controls are in place to ensure that customer PII is stored in Cloud Storage buckets without third-party exposure. Which Google Cloud solution should the organization use to verify that PII is stored in the correct place without exposing PII internally?

  • A. Cloud Data Loss Prevention API
  • B. Cloud Security Scanner
  • C. Cloud Storage Bucket Lock
  • D. VPC Service Controls

Answer: A

Explanation:
A is not correct because Bucket Lock feature is for protecting the data retention policy and doesn't address the use case.
B is correct because Cloud Data Loss Prevention API can be used to inspect Cloud Storage buckets for PII.
C is not correct because while VPC Service Controls can allow customers to define security perimeters around Cloud Storage Buckets in order to mitigate data exfiltration risks, it's not a tool to locate PIIs hence doesn't address this use case.
D is not correct because Cloud Security Scanner is a web security scanner for App Engine, Compute Engine, and Google Kubernetes Engine applications and doesn't address the use case.
https://cloud.google.com/storage/docs/bucket-lock
https://cloud.google.com/dlp/docs/inspecting-storage#inspecting-gcs
https://cloud.google.com/vpc-service-controls/
https://cloud.google.com/security-scanner/

 

NEW QUESTION 29
An organization adopts Google Cloud Platform (GCP) for application hosting services and needs guidance on setting up password requirements for their Cloud Identity account. The organization has a password policy requirement that corporate employee passwords must have a minimum number of characters.
Which Cloud Identity password guidelines can the organization use to inform their new requirements?

  • A. Set the minimum length for passwords to be 12 characters.
  • B. Set the minimum length for passwords to be 10 characters.
  • C. Set the minimum length for passwords to be 6 characters.
  • D. Set the minimum length for passwords to be 8 characters.

Answer: A

 

NEW QUESTION 30
A company is running workloads in a dedicated server room. They must only be accessed from within the private company network. You need to connect to these workloads from Compute Engine instances within a Google Cloud Platform project.
Which two approaches can you take to meet the requirements? (Choose two.)

  • A. Configure the project with Cloud Interconnect.
  • B. Configure the project with Shared VPC.
  • C. Configure the project with VPC peering.
  • D. Configure the project with Cloud VPN.
  • E. Configure all Compute Engine instances with Private Access.

Answer: C,E

Explanation:
https://cloud.google.com/solutions/secure-data-workloads-use-cases

 

NEW QUESTION 31
You are on your company's development team. You noticed that your web application hosted in staging on GKE dynamically includes user data in web pages without first properly validating the inputted dat a. This could allow an attacker to execute gibberish commands and display arbitrary content in a victim user's browser in a production environment.
How should you prevent and fix this vulnerability?

  • A. Use Web Security Scanner to validate the usage of an outdated library in the code, and then use a secured version of the included library.
  • B. Use Web Security Scanner in staging to simulate an XSS injection attack, and then use a templating system that supports contextual auto-escaping.
  • C. Use Cloud IAP based on IP address or end-user device attributes to prevent and fix the vulnerability.
  • D. Set up an HTTPS load balancer, and then use Cloud Armor for the production environment to prevent the potential XSS attack.

Answer: B

Explanation:
Reference:
https://cloud.google.com/security-scanner/docs/remediate-findings

 

NEW QUESTION 32
Your team wants to make sure Compute Engine instances running in your production project do not have public IP addresses. The frontend application Compute Engine instances will require public IPs. The product engineers have the Editor role to modify resources. Your team wants to enforce this requirement.
How should your team meet these requirements?

  • A. Set up an organization policy to only permit public IPs for the front-end Compute Engine instances.
  • B. Set up a VPC network with two subnets: one with public IPs and one without public IPs.
  • C. Remove the Editor role and grant the Compute Admin IAM role to the engineers.
  • D. Enable Private Access on the VPC network in the production project.

Answer: A

Explanation:
Reference:
https://cloud.google.com/compute/docs/ip-addresses/reserve-static-external-ip-address

 

NEW QUESTION 33
You want to limit the images that can be used as the source for boot disks. These images will be stored in a dedicated project.
What should you do?

  • A. Use the Organization Policy Service to create a compute.trustedimageProjects constraint on the organization level. List the trusted project as the whitelist in an allow operation.
  • B. In Resource Manager, edit the project permissions for the trusted project. Add the organization as member with the role: Compute Image User.
  • C. Use the Organization Policy Service to create a compute.trustedimageProjects constraint on the organization level. List the trusted projects as the exceptions in a deny operation.
  • D. In Resource Manager, edit the organization permissions. Add the project ID as member with the role:
    Compute Image User.

Answer: C

Explanation:
https://cloud.google.com/compute/docs/images/restricting-image-access

 

NEW QUESTION 34
Last week, a company deployed a new App Engine application that writes logs to BigQuery. No other workloads are running in the project. You need to validate that all data written to BigQuery was done using the App Engine Default Service Account.
What should you do?

  • A. 1. Use StackDriver Logging and filter on BigQuery Insert Jobs.
    2. Click on the email address in line with the App Engine Default Service Account in the authentication field.
    3. Click Hide Matching Entries.
    4. Make sure the resulting list is empty.
  • B. 1. Use StackDriver Logging and filter on BigQuery Insert Jobs.
    2. Click on the email address in line with the App Engine Default Service Account in the authentication field.
    3. Click Show Matching Entries.
    4. Make sure the resulting list is empty.
  • C. 1. In BigQuery, select the related dataset.
    2. Make sure the App Engine Default Service Account is the only account that can write to the dataset.
  • D. 1. Go to the IAM section on the project.
    2. Validate that the App Engine Default Service Account is the only account that has a role that can write to BigQuery.
    Section: (none)
    Explanation

Answer: C

 

NEW QUESTION 35
An organization receives an increasing number of phishing emails.
Which method should be used to protect employee credentials in this situation?

  • A. Multifactor Authentication
  • B. A strict password policy
  • C. Encrypted emails
  • D. Captcha on login pages

Answer: C

 

NEW QUESTION 36
Your team uses a service account to authenticate data transfers from a given Compute Engine virtual machine instance of to a specified Cloud Storage bucket. An engineer accidentally deletes the service account, which breaks application functionality. You want to recover the application as quickly as possible without compromising security.
What should you do?

  • A. Create a new service account with the same name as the deleted service account.
  • B. Temporarily disable authentication on the Cloud Storage bucket.
  • C. Use the undelete command to recover the deleted service account.
  • D. Update the permissions of another existing service account and supply those credentials to the applications.

Answer: C

 

NEW QUESTION 37
......

Test Engine to Practice Professional-Cloud-Security-Engineer Test Questions: https://actual4test.practicetorrent.com/Professional-Cloud-Security-Engineer-practice-exam-torrent.html