Professional-Cloud-Security-Engineer Exam Dumps - PDF Questions and Testing Engine [Q19-Q42]

Share

Professional-Cloud-Security-Engineer Exam Dumps - PDF Questions and Testing Engine

Professional-Cloud-Security-Engineer Dumps - The Sure Way To Pass Exam

NEW QUESTION 19
A customer wants to grant access to their application running on Compute Engine to write only to a specific Cloud Storage bucket. How should you grant access?

  • A. Create a user account, authenticate with the application, and grant Google Storage Admin permissions at the bucket level.
  • B. Create a user account, authenticate with the application, and grant Google Storage Admin permissions at the project leve
  • C. Create a service account for the application, and grant Cloud Storage Object Creator permissions at the bucket level.
  • D. Create a service account for the application, and grant Cloud Storage Object Creator permissions to the project.

Answer: C

Explanation:
A is not correct because it doesn't restrict the scope to specific bucket.
B is correct because it provides the right permissions and keeps the scope limited to the bucket in question.
C is not correct because using a user account goes against the recommended best practice as it should be a machine/service account that should be handling the writing to bucket.
D is not correct because using a user account goes against the recommended best practice as it should be a machine/service account that should be handling the writing to bucket and it also widens the scope to storage wide which violates minimum required privilege rules.
https://cloud.google.com/iam/docs/understanding-service-
accounts#using_service_accounts_with_compute_engine

 

NEW QUESTION 20
A company is running workloads in a dedicated server room. They must only be accessed from within the private company network. You need to connect to these workloads from Compute Engine instances within a Google Cloud Platform project.
Which two approaches can you take to meet the requirements? (Choose two.)

  • A. Configure the project with Cloud Interconnect.
  • B. Configure the project with VPC peering.
  • C. Configure the project with Cloud VPN.
  • D. Configure the project with Shared VPC.
  • E. Configure all Compute Engine instances with Private Access.

Answer: B,E

Explanation:
https://cloud.google.com/solutions/secure-data-workloads-use-cases

 

NEW QUESTION 21
Your team sets up a Shared VPC Network where project co-vpc-prod is the host project. Your team has configured the firewall rules, subnets, and VPN gateway on the host project. They need to enable Engineering Group A to attach a Compute Engine instance to only the 10.1.1.0/24 subnet.
What should your team grant to Engineering Group A to meet this requirement?

  • A. Compute Shared VPC Admin Role at the host project level.
  • B. Compute Shared VPC Admin Role at the service project level.
  • C. Compute Network User Role at the subnet level.
  • D. Compute Network User Role at the host project level.

Answer: A

Explanation:
Reference:
https://cloud.google.com/vpc/docs/shared-vpc

 

NEW QUESTION 22
A manager wants to start retaining security event logs for 2 years while minimizing costs. You write a filter to select the appropriate log entries.
Where should you export the logs?

  • A. Cloud Storage buckets
  • B. StackDriver logging
  • C. Cloud Pub/Sub topics
  • D. BigQuery datasets

Answer: B

Explanation:
https://cloud.google.com/logging/docs/exclusions

 

NEW QUESTION 23
Your organization has had a few recent DDoS attacks. You need to authenticate responses to domain name lookups. Which Google Cloud service should you use?

  • A. Cloud DNS with DNSSEC
  • B. Cloud NAT
  • C. HTTP(S) Load Balancing
  • D. Google Cloud Armor

Answer: A

 

NEW QUESTION 24
An organization is moving applications to Google Cloud while maintaining a few mission-critical applications on-premises. The organization must transfer the data at a bandwidth of at least 50 Gbps. What should they use to ensure secure continued connectivity between sites?

  • A. Cloud Router
  • B. Partner Interconnect
  • C. Dedicated Interconnect
  • D. Cloud VPN

Answer: C

 

NEW QUESTION 25
Your customer is moving their corporate applications to Google Cloud Platform. The security team wants detailed visibility of all resources in the organization. You use Resource Manager to set yourself up as the org admin. What Cloud Identity and Access Management (Cloud IAM) roles should you give to the security team?

  • A. Org viewer, Project owner
  • B. Project owner, Network admin
  • C. Org admin, Project browser
  • D. Org viewer, Project viewer

Answer: D

Explanation:
A is not correct because Project owner is too broad. The security team does not need to be able to make changes to projects.
B is correct because:
- Org viewer grants the security team permissions to view the organization's display name.
- Project viewer grants the security team permissions to see the resources within projects.
C is not correct because Org admin is too broad. The security team does not need to be able to make changes to the organization.
D is not correct because Project owner is too broad. The security team does not need to be able to make changes to projects.
https://cloud.google.com/resource-manager/docs/access-control-org#using_predefined_roles

 

NEW QUESTION 26
Applications often require access to "secrets" - small pieces of sensitive data at build or run time. The administrator managing these secrets on GCP wants to keep a track of "who did what, where, and when?" within their GCP projects.
Which two log streams would provide the information that the administrator is looking for? (Choose two.)

  • A. VPC Flow logs
  • B. Agent logs
  • C. Admin Activity logs
  • D. Data Access logs
  • E. System Event logs

Answer: C,D

 

NEW QUESTION 27
You need to follow Google-recommended practices to leverage envelope encryption and encrypt data at the application layer.
What should you do?

  • A. Generate a data encryption key (DEK) locally to encrypt the data, and generate a new key encryption key (KEK) in Cloud KMS to encrypt the DEK. Store both the encrypted data and the encrypted DEK.
  • B. Generate a data encryption key (DEK) locally to encrypt the data, and generate a new key encryption key (KEK) in Cloud KMS to encrypt the DEK. Store both the encrypted data and the KEK.
  • C. Generate a new data encryption key (DEK) in Cloud KMS to encrypt the data, and generate a key encryption key (KEK) locally to encrypt the key. Store both the encrypted data and the encrypted DEK.
  • D. Generate a new data encryption key (DEK) in Cloud KMS to encrypt the data, and generate a key encryption key (KEK) locally to encrypt the key. Store both the encrypted data and the KEK.

Answer: A

Explanation:
Reference:
https://cloud.google.com/kms/docs/envelope-encryption

 

NEW QUESTION 28
A customer's data science group wants to use Google Cloud Platform (GCP) for their analytics workloads.
Company policy dictates that all data must be company-owned and all user authentications must go through their own Security Assertion Markup Language (SAML) 2.0 Identity Provider (IdP). The Infrastructure Operations Systems Engineer was trying to set up Cloud Identity for the customer and realized that their domain was already being used by G Suite.
How should you best advise the Systems Engineer to proceed with the least disruption?

  • A. Ask customer's management to discover any other uses of Google managed services, and work with the existing Super Administrator.
  • B. Ask Google to provision the data science manager's account as a Super Administrator in the existing domain.
  • C. Register a new domain name, and use that for the new Cloud Identity domain.
  • D. Contact Google Support and initiate the Domain Contestation Process to use the domain name in your new Cloud Identity domain.

Answer: B

 

NEW QUESTION 29
While migrating your organization's infrastructure to GCP, a large number of users will need to access GCP Console. The Identity Management team already has a well-established way to manage your users and want to keep using your existing Active Directory or LDAP server along with the existing SSO password.
What should you do?

  • A. Use Google Cloud Directory Sync to synchronize the data in Google domain with your existing Active Directory or LDAP server.
  • B. Users sign in using OpenID (OIDC) compatible IdP, receive an authentication token, then use that token to log in to the GCP Console.
  • C. Manually synchronize the data in Google domain with your existing Active Directory or LDAP server.
  • D. Users sign in directly to the GCP Console using the credentials from your on-premises Kerberos compliant identity provider.

Answer: A

Explanation:
Explanation/Reference: https://cloud.google.com/blog/products/identity-security/using-your-existing-identity-management- system-with-google-cloud-platform

 

NEW QUESTION 30
An organization is migrating from their current on-premises productivity software systems to G Suite. Some network security controls were in place that were mandated by a regulatory body in their region for their previous on-premises system. The organization's risk team wants to ensure that network security controls are maintained and effective in G Suite. A security architect supporting this migration has been asked to ensure that network security controls are in place as part of the new shared responsibility model between the organization and Google Cloud.
What solution would help meet the requirements?

  • A. Ensure that firewall rules are in place to meet the required controls.
  • B. Network security is a built-in solution and Google's Cloud responsibility for SaaS products like G Suite.
  • C. Set up an array of Virtual Private Cloud (VPC) networks to control network security as mandated by the relevant regulation.
  • D. Set up Cloud Armor to ensure that network security controls can be managed for G Suite.

Answer: B

Explanation:
https://gsuite.google.com/learn-more/security/security-whitepaper/page-1.html

 

NEW QUESTION 31
You are asked to recommend a solution to store and retrieve sensitive configuration data from an application that runs on Compute Engine. Which option should you recommend?

  • A. Secret Manager
  • B. Compute Engine custom metadata
  • C. Compute Engine guest attributes
  • D. Cloud Key Management Service

Answer: D

 

NEW QUESTION 32
You are part of a security team that wants to ensure that a Cloud Storage bucket in Project A can only be readable from Project B.
You also want to ensure that data in the Cloud Storage bucket cannot be accessed from or copied to Cloud Storage buckets outside the network, even if the user has the correct credentials.
What should you do?

  • A. Enable VPC Peering between Project A and B networks with strict firewall rules to allow communication between the networks.
  • B. Enable Domain Restricted Sharing Organization Policy and Bucket Policy Only on the Cloud Storage bucket.
  • C. Enable VPC Service Controls, create a perimeter with Project A and B, and include Cloud Storage service.
  • D. Enable Private Access in Project A and B networks with strict firewall rules to allow communication between the networks.

Answer: B

 

NEW QUESTION 33
Your team wants to centrally manage GCP IAM permissions from their on-premises Active Directory Service. Your team wants to manage permissions by AD group membership.
What should your team do to meet these requirements?

  • A. Set up SAML 2.0 Single Sign-On (SSO), and assign IAM permissions to the groups.
  • B. Set up Cloud Directory Sync to sync groups, and set IAM permissions on the groups.
  • C. Use the Admin SDK to create groups and assign IAM permissions from Active Directory.
  • D. Use the Cloud Identity and Access Management API to create groups and IAM permissions from Active Directory.

Answer: A

Explanation:
https://cloud.google.com/blog/products/identity-security/using-your-existing-identity-management- system-with-google-cloud-platform

 

NEW QUESTION 34
A customer needs to launch a 3-tier internal web application on Google Cloud Platform (GCP). The customer's internal compliance requirements dictate that end-user access may only be allowed if the traffic seems to originate from a specific known good CIDR. The customer accepts the risk that their application will only have SYN flood DDoS protection. They want to use GCP's native SYN flood protection.
Which product should be used to meet these requirements?

  • A. Cloud CDN
  • B. Cloud Identity and Access Management
  • C. VPC Firewall Rules
  • D. Cloud Armor

Answer: D

Explanation:
Explanation/Reference: https://cloud.google.com/blog/products/identity-security/understanding-google-cloud-armors-new- waf-capabilities

 

NEW QUESTION 35
An organization's security and risk management teams are concerned about where their responsibility lies for certain production workloads they are running in Google Cloud Platform (GCP), and where Google's responsibility lies. They are mostly running workloads using Google Cloud's Platform-as-a-Service (PaaS) offerings, including App Engine primarily.
Which one of these areas in the technology stack would they need to focus on as their primary responsibility when using App Engine?

  • A. Encrypting all stored data
  • B. Manage the latest updates and security patches for the Guest OS
  • C. Defending against XSS and SQLi attacks
  • D. Configuring and monitoring VPC Flow Logs

Answer: C

 

NEW QUESTION 36
You are a member of the security team at an organization. Your team has a single GCP project with credit card payment processing systems alongside web applications and data processing systems. You want to reduce the scope of systems subject to PCI audit standards.
What should you do?

  • A. Use VPN for all connections between your office and cloud environments.
  • B. Use only applications certified compliant with PA-DSS.
  • C. Use multi-factor authentication for admin access to the web application.
  • D. Move the cardholder data environment into a separate GCP project.

Answer: A

Explanation:
Reference:
https://cloud.google.com/solutions/pci-dss-compliance-in-gcp

 

NEW QUESTION 37
Your company is using Cloud Dataproc for its Spark and Hadoop jobs. You want to be able to create, rotate, and destroy symmetric encryption keys used for the persistent disks used by Cloud Dataproc. Keys can be stored in the cloud.
What should you do?

  • A. Use the Cloud Key Management Service to manage the data encryption key (DEK).
  • B. Use customer-supplied encryption keys to manage the key encryption key (KEK).
  • C. Use customer-supplied encryption keys to manage the data encryption key (DEK).
  • D. Use the Cloud Key Management Service to manage the key encryption key (KEK).

Answer: A

 

NEW QUESTION 38
You are a member of your company's security team. You have been asked to reduce your Linux bastion host external attack surface by removing all public IP addresses. Site Reliability Engineers (SREs) require access to the bastion host from public locations so they can access the internal VPC while off-site. How should you enable this access?

  • A. Implement Identity-Aware Proxy TCP forwarding for the bastion host.
  • B. Implement Cloud VPN for the region where the bastion host lives.
  • C. Implement Google Cloud Armor in front of the bastion host.
  • D. Implement OS Login with 2-step verification for the bastion host.

Answer: A

 

NEW QUESTION 39
Your company wants to collect and analyze CVE information for packages in container images, and wants to prevent images with known security issues from running in your Google Kubernetes Engine environment. Which two security features does Google recommend including in a container build pipeline?

  • A. Vulnerability scanning
  • B. Network isolation
  • C. Password policies
  • D. Deployment policies

Answer: D

Explanation:
A is correct because deployment policies defined in Binary Authorization ensure that only trusted images can be deployed in Google Kubernetes Engine clusters. Binary Authorization can integrate with Container Analysis which scans container images stored in Container Registry for vulnerabilities and stores trusted metadata used in the authorization process.
B is not correct because it doesn't address the use case.
C is correct because vulnerability scanning can be performed by Container Analysis to discover package vulnerability information in container base images and obtain CVE data from respective Linux distributions.
D is not correct because it doesn't address the use case.
https://cloud.google.com/binary-authorization/docs/overview
https://cloud.google.com/container-registry/docs/container-analysis

 

NEW QUESTION 40
An engineering team is launching a web application that will be public on the internet. The web application is hosted in multiple GCP regions and will be directed to the respective backend based on the URL request.
Your team wants to avoid exposing the application directly on the internet and wants to deny traffic from a specific list of malicious IP addresses Which solution should your team implement to meet these requirements?

  • A. Network Load Balancing
  • B. NAT Gateway
  • C. Cloud Armor
  • D. SSL Proxy Load Balancing

Answer: C

Explanation:
Explanation
Explanation/Reference: https://cloud.google.com/armor/docs/security-policy-concepts

 

NEW QUESTION 41
An engineering team is launching a web application that will be public on the internet. The web application is hosted in multiple GCP regions and will be directed to the respective backend based on the URL request.
Your team wants to avoid exposing the application directly on the internet and wants to deny traffic from a specific list of malicious IP addresses Which solution should your team implement to meet these requirements?

  • A. Network Load Balancing
  • B. NAT Gateway
  • C. Cloud Armor
  • D. SSL Proxy Load Balancing

Answer: C

Explanation:
Explanation/Reference: https://cloud.google.com/armor/docs/security-policy-concepts

 

NEW QUESTION 42
......

Pass Google Professional-Cloud-Security-Engineer Exam Quickly With ValidDumps: https://www.validdumps.top/Professional-Cloud-Security-Engineer-exam-torrent.html

Professional-Cloud-Security-Engineer Exam Questions (Updated 2022) 100% Real Question Answers: https://drive.google.com/open?id=16sMkCSu5rpx7e0Y0tdBO3c06FdfY_xmV