Your team needs to make sure that a Compute Engine instance does not have access to the internet or to any Google APIs or services.Which two settings must remain disabled to meet these requirements? (Choose two.)
Answer(s): A,C
https://cloud.google.com/vpc/docs/configure-private-google-access
Which two implied firewall rules are defined on a VPC network? (Choose two.)
Answer(s): A,B
Implied IPv4 allow egress rule. An egress rule whose action is allow, destination is 0.0.0.0/0, and priority is the lowest possible (65535) lets any instance send traffic to any destinationImplied IPv4 deny ingress rule. An ingress rule whose action is deny, source is 0.0.0.0/0, and priority is the lowest possible (65535) protects all instances by blocking incoming connections to them.https://cloud.google.com/vpc/docs/firewalls?hl=en#default_firewall_rules
A customer needs an alternative to storing their plain text secrets in their source-code management (SCM) system.How should the customer achieve this using Google Cloud Platform?
Answer(s): B
Your team wants to centrally manage GCP IAM permissions from their on-premises Active Directory Service. Your team wants to manage permissions by AD group membership.What should your team do to meet these requirements?
Answer(s): A
"In order to be able to keep using the existing identity management system, identities need to be synchronized between AD and GCP IAM. To do so google provides a tool called Cloud Directory Sync. This tool will read all identities in AD and replicate those within GCP. Once the identities have been replicated then it's possible to apply IAM permissions on the groups. After that you will configure SAML so google can act as a service provider and either you ADFS or other third party tools like Ping or Okta will act as the identity provider. This way you effectively delegate the authentication from Google to something that is under your control."
Post your Comments and Discuss Google Professional Cloud Security Engineer exam prep with other Community members:
ds Commented on January 12, 2025 good resource Anonymous
ph Commented on December 29, 2024 q92 was badly written and not clear on what it was asking Anonymous
Kapal Commented on April 08, 2021 Just passed the exam today. Worth the money! UNITED KINGDOM
We’re offering these study questions to support your success. The least you can do? Drop a useful comment about each question. Help others. Build the community.