
Actual Professional-Cloud-Security-Engineer Exam Recently Updated Questions with Free Demo
Free Google Professional-Cloud-Security-Engineer Exam Questions Self-Assess Preparation
Google Professional-Cloud-Security-Engineer certification is a highly respected and in-demand certification offered by Google Cloud. Google Cloud Certified - Professional Cloud Security Engineer Exam certification program is designed for IT professionals who are responsible for designing, implementing and managing security solutions in the Google Cloud environment. Google Cloud Certified - Professional Cloud Security Engineer Exam certification exam assesses a candidate's knowledge and skills in securing the GCP infrastructure and services, managing identity and access, ensuring data protection and compliance, and managing incident response.
NEW QUESTION # 103
Your organization wants to be compliant with the General Data Protection Regulation (GDPR) on Google Cloud You must implement data residency and operational sovereignty in the EU.
What should you do?
Choose 2 answers
- A. Use Cloud IDS to get east-west and north-south traffic visibility in the EU to monitor intra-VPC and mter-VPC communication.
- B. Limit the physical location of a new resource with the Organization Policy Service resource locations constraint."
- C. Limit Google personnel access based on predefined attributes such as their citizenship or geographic location by using Key Access Justifications
- D. Use VPC Flow Logs to monitor intra-VPC and inter-VPC traffic in the EU.
- E. Use identity federation to limit access to Google Cloud resources from non-EU entities.
Answer: B,C
Explanation:
Explanation
https://cloud.google.com/architecture/framework/security/data-residency-sovereignty#manage_your_operational
NEW QUESTION # 104
A customer is running an analytics workload on Google Cloud Platform (GCP) where Compute Engine instances are accessing data stored on Cloud Storage. Your team wants to make sure that this workload will not be able to access, or be accessed from, the internet.
Which two strategies should your team use to meet these requirements? (Choose two.)
- A. Turn off IP forwarding on the Compute Engine instances in the cluster.
- B. Avoid assigning public IP addresses to the Compute Engine cluster.
- C. Configure a Cloud NAT gateway.
- D. Configure Private Google Access on the Compute Engine subnet
- E. Make sure that the Compute Engine cluster is running on a separate subnet.
Answer: B,C
NEW QUESTION # 105
You are on your company's development team. You noticed that your web application hosted in staging on GKE dynamically includes user data in web pages without first properly validating the inputted data. This could allow an attacker to execute gibberish commands and display arbitrary content in a victim user's browser in a production environment.
How should you prevent and fix this vulnerability?
- A. Use Web Security Scanner in staging to simulate an XSS injection attack, and then use a templating system that supports contextual auto-escaping.
- B. Use Web Security Scanner to validate the usage of an outdated library in the code, and then use a secured version of the included library.
- C. Use Cloud IAP based on IP address or end-user device attributes to prevent and fix the vulnerability.
- D. Set up an HTTPS load balancer, and then use Cloud Armor for the production environment to prevent the potential XSS attack.
Answer: A
Explanation:
https://cloud.google.com/security-scanner/docs/remediate-findings
NEW QUESTION # 106
In an effort for your company messaging app to comply with FIPS 140-2, a decision was made to use GCP compute and network services. The messaging app architecture includes a Managed Instance Group (MIG) that controls a cluster of Compute Engine instances. The instances use Local SSDs for data caching and UDP for instance-to-instance communications. The app development team is willing to make any changes necessary to comply with the standard Which options should you recommend to meet the requirements?
- A. Set Disk Encryption on the Instance Template used by the MIG to customer-managed key and use BoringSSL for all data transit between instances.
- B. Set Disk Encryption on the Instance Template used by the MIG to Google-managed Key and use BoringSSL library on all instance-to-instance communications.
- C. Encrypt all cache storage and VM-to-VM communication using the BoringCrypto module.
- D. Change the app instance-to-instance communications from UDP to TCP and enable BoringSSL on clients' TLS connections.
Answer: B
NEW QUESTION # 107
Applications often require access to "secrets" - small pieces of sensitive data at build or run time. The administrator managing these secrets on GCP wants to keep a track of "who did what, where, and when?" within their GCP projects.
Which two log streams would provide the information that the administrator is looking for? (Choose two.)
- A. System Event logs
- B. Agent logs
- C. Data Access logs
- D. VPC Flow logs
- E. Admin Activity logs
Answer: C,E
Explanation:
https://cloud.google.com/secret-manager/docs/audit-logging
NEW QUESTION # 108
Applications often require access to "secrets" -small pieces of sensitive data at build or run time.
The administrator managing these secrets on GCP wants to keep a track of "who did what, where, and when?" within their GCP projects.
Which two log streams would provide the information that the administrator is looking for?
(Choose two.)
- A. System Event logs
- B. Agent logs
- C. Data Access logs
- D. VPC Flow logs
- E. Admin Activity logs
Answer: C,E
Explanation:
https://cloud.google.com/kms/docs/secret-management
NEW QUESTION # 109
An organization is evaluating the use of Google Cloud Platform (GCP) for certain IT workloads. A well- established directory service is used to manage user identities and lifecycle management. This directory service must continue for the organization to use as the "source of truth" directory for identities.
Which solution meets the organization's requirements?
- A. Google Cloud Directory Sync (GCDS)
- B. Security Assertion Markup Language (SAML)
- C. Pub/Sub
- D. Cloud Identity
Answer: D
Explanation:
Reference:
https://cloud.google.com/solutions/federating-gcp-with-active-directory-introduction
NEW QUESTION # 110
A patch for a vulnerability has been released, and a DevOps team needs to update their running containers in Google Kubernetes Engine (GKE).
How should the DevOps team accomplish this?
- A. Use Puppet or Chef to push out the patch to the running container.
- B. Configure containers to automatically upgrade when the base image is available in Container Registry.
- C. Update the application code or apply a patch, build a new image, and redeploy it.
- D. Verify that auto upgrade is enabled; if so, Google will upgrade the nodes in a GKE cluster.
Answer: D
NEW QUESTION # 111
Your company's chief information security officer (CISO) is requiring business data to be stored in specific locations due to regulatory requirements that affect the company's global expansion plans. After working on a plan to implement this requirement, you determine the following:
* The services in scope are included in the Google Cloud data residency requirements.
* The business data remains within specific locations under the same organization.
* The folder structure can contain multiple data residency locations.
* The projects are aligned to specific locations.
You plan to use the Resource Location Restriction organization policy constraint with very granular control.
At which level in the hierarchy should you set the constraint?
- A. Folder
- B. Project
- C. Resource
- D. Organization
Answer: B
NEW QUESTION # 112
Your organization wants to be compliant with the General Data Protection Regulation (GDPR) on Google Cloud You must implement data residency and operational sovereignty in the EU.
What should you do?
Choose 2 answers
- A. Use Cloud IDS to get east-west and north-south traffic visibility in the EU to monitor intra-VPC and mter-VPC communication.
- B. Limit the physical location of a new resource with the Organization Policy Service resource locations constraint."
- C. Limit Google personnel access based on predefined attributes such as their citizenship or geographic location by using Key Access Justifications
- D. Use VPC Flow Logs to monitor intra-VPC and inter-VPC traffic in the EU.
- E. Use identity federation to limit access to Google Cloud resources from non-EU entities.
Answer: B,C
Explanation:
https://cloud.google.com/architecture/framework/security/data-residency-sovereignty#manage_your_operational_sovereignty
NEW QUESTION # 113
A company migrated their entire data/center to Google Cloud Platform. It is running thousands of instances across multiple projects managed by different departments. You want to have a historical record of what was running in Google Cloud Platform at any point in time.
What should you do?
- A. Use Security Command Center to view all assets across the organization.
- B. Use Stackdriver to create a dashboard across all projects.
- C. Use Forseti Security to automate inventory snapshots.
- D. Use Resource Manager on the organization level.
Answer: C
Explanation:
Only Forseti security can have both 'past' and 'present' (i.e. historical) records of the resources. https://forsetisecurity.org/about/
NEW QUESTION # 114
A company has been running their application on Compute Engine. A bug in the application allowed a malicious user to repeatedly execute a script that results in the Compute Engine instance crashing. Although the bug has been fixed, you want to get notified in case this hack re-occurs.
What should you do?
- A. Log every execution of the script to Stackdriver Logging. Configure BigQuery as a log sink, and create a BigQuery scheduled query to count the number of executions in a specific timeframe.
- B. Create an Alerting Policy in Stackdriver using a Process Health condition, checking that the number of executions of the script remains below the desired threshold. Enable notifications.
- C. Log every execution of the script to Stackdriver Logging. Create a User-defined metric in Stackdriver Logging on the logs, and create a Stackdriver Dashboard displaying the metric.
- D. Create an Alerting Policy in Stackdriver using the CPU usage metric. Set the threshold to 80% to be notified when the CPU usage goes above this 80%.
Answer: C
Explanation:
Reference:
https://cloud.google.com/logging/docs/logs-based-metrics/
NEW QUESTION # 115
Your team wants to make sure Compute Engine instances running in your production project do not have public IP addresses. The frontend application Compute Engine instances will require public IPs. The product engineers have the Editor role to modify resources. Your team wants to enforce this requirement.
How should your team meet these requirements?
- A. Remove the Editor role and grant the Compute Admin IAM role to the engineers.
- B. Set up a VPC network with two subnets: one with public IPs and one without public IPs.
- C. Set up an organization policy to only permit public IPs for the front-end Compute Engine instances.
- D. Enable Private Access on the VPC network in the production project.
Answer: C
Explanation:
Explanation/Reference: https://cloud.google.com/compute/docs/ip-addresses/reserve-static-external-ip-address
NEW QUESTION # 116
Your team sets up a Shared VPC Network where project co-vpc-prod is the host project. Your team has configured the firewall rules, subnets, and VPN gateway on the host project. They need to enable Engineering Group A to attach a Compute Engine instance to only the 10.1.1.0/24 subnet.
What should your team grant to Engineering Group A to meet this requirement?
- A. Compute Network User Role at the host project level.
- B. Compute Shared VPC Admin Role at the service project level.
- C. Compute Network User Role at the subnet level.
- D. Compute Shared VPC Admin Role at the host project level.
Answer: C
Explanation:
https://cloud.google.com/vpc/docs/shared-vpc#svc_proj_admins
NEW QUESTION # 117
You need to connect your organization's on-premises network with an existing Google Cloud environment that includes one Shared VPC with two subnets named Production and Non-Production. You are required to:
Use a private transport link.
Configure access to Google Cloud APIs through private API endpoints originating from on-premises environments.
Ensure that Google Cloud APIs are only consumed via VPC Service Controls.
What should you do?
- A. 1. Set up a Partner Interconnect link between the on-premises environment and Google Cloud.
2. Configure private access using the private.googleapis.com domains in on-premises DNS configurations. - B. 1. Set up a Cloud VPN link between the on-premises environment and Google Cloud.
2. Configure private access using the restricted googleapis.com domains in on-premises DNS configurations. - C. 1. Set up a Direct Peering link between the on-premises environment and Google Cloud.
2. Configure private access for both VPC subnets. - D. 1. Set up a Dedicated Interconnect link between the on-premises environment and Google Cloud.
2. Configure private access using the restricted.googleapis.com domains in on-premises DNS configurations.
Answer: C
NEW QUESTION # 118
You are the security admin of your company. You have 3,000 objects in your Cloud Storage bucket. You do not want to manage access to each object individually. You also do not want the uploader of an object to always have full control of the object. However, you want to use Cloud Audit Logs to manage access to your bucket.
What should you do?
- A. Set up a default bucket ACL and manage access for users using IAM.
- B. Set up Uniform bucket-level access on the Cloud Storage bucket and manage access for users using IAM.
- C. Set up an ACL with READER permission to a scope of allUsers.
- D. Set up an ACL with OWNER permission to a scope of allUsers.
Answer: D
Explanation:
Reference:
https://cloud.google.com/storage/docs/access-control/lists
NEW QUESTION # 119
......
To prepare for the Professional-Cloud-Security-Engineer certification exam, Google offers a variety of training resources such as online courses, practice tests, and certification guides. Additionally, Google recommends having hands-on experience with Google Cloud Platform and familiarity with the relevant concepts and objectives of the certification exam. Google also offers a community platform where individuals can interact with other professionals, share their knowledge, and learn from the experiences of others.
Achieving the Google Professional-Cloud-Security-Engineer certification demonstrates an individual's expertise in securing applications and data within the GCP environment. Google Cloud Certified - Professional Cloud Security Engineer Exam certification can help IT professionals advance their careers and demonstrate their value to organizations looking to adopt GCP for their cloud infrastructure.
Professional-Cloud-Security-Engineer Free Sample Questions to Practice One Year Update: https://www.torrentvce.com/Professional-Cloud-Security-Engineer-valid-vce-collection.html
Download Professional-Cloud-Security-Engineer exam with Google Professional-Cloud-Security-Engineer Real Exam Questions: https://drive.google.com/open?id=1SRQr1ju3M18XLzTuxDXz_KEiDWSU8y7c