Free Google PROFESSIONAL-CLOUD-SECURITY-ENGINEER Exam Questions (page: 7)

An organization is migrating from their current on-premises productivity software systems to G Suite. Some network security controls were in place that were mandated by a regulatory body in their region for their previous on-premises system. The organization's risk team wants to ensure that network security controls are maintained and effective in G Suite. A security architect supporting this migration has been asked to ensure that network security controls are in place as part of the new shared responsibility model between the organization and Google Cloud.

What solution would help meet the requirements?

  1. Ensure that firewall rules are in place to meet the required controls.
  2. Set up Cloud Armor to ensure that network security controls can be managed for G Suite.
  3. Network security is a built-in solution and Google's Cloud responsibility for SaaS products like G Suite.
  4. Set up an array of Virtual Private Cloud (VPC) networks to control network security as mandated by the relevant regulation.

Answer(s): C



A customer's company has multiple business units. Each business unit operates independently, and each has their own engineering group. Your team wants visibility into all projects created within the company and wants to organize their Google Cloud Platform (GCP) projects based on different business units. Each business unit also requires separate sets of IAM permissions.

Which strategy should you use to meet these needs?

  1. Create an organization node, and assign folders for each business unit.
  2. Establish standalone projects for each business unit, using gmail.com accounts.
  3. Assign GCP resources in a project, with a label identifying which business unit owns the resource.
  4. Assign GCP resources in a VPC for each business unit to separate network access.

Answer(s): A



A company has redundant mail servers in different Google Cloud Platform regions and wants to route customers to the nearest mail server based on location.

How should the company accomplish this?

  1. Configure TCP Proxy Load Balancing as a global load balancing service listening on port 995.
  2. Create a Network Load Balancer to listen on TCP port 995 with a forwarding rule to forward traffic based on location.
  3. Use Cross-Region Load Balancing with an HTTP(S) load balancer to route traffic to the nearest region.
  4. Use Cloud CDN to route the mail traffic to the closest origin mail server based on client IP address.

Answer(s): A



Your team sets up a Shared VPC Network where project co-vpc-prod is the host project. Your team has configured the firewall rules, subnets, and VPN gateway on the host project. They need to enable Engineering Group A to attach a Compute Engine instance to only the 10.1.1.0/24 subnet.

What should your team grant to Engineering Group A to meet this requirement?

  1. Compute Network User Role at the host project level.
  2. Compute Network User Role at the subnet level.
  3. Compute Shared VPC Admin Role at the host project level.
  4. Compute Shared VPC Admin Role at the service project level.

Answer(s): B


Reference:

https://cloud.google.com/vpc/docs/shared-vpc



A company migrated their entire data/center to Google Cloud Platform. It is running thousands of instances across multiple projects managed by different departments. You want to have a historical record of what was running in Google Cloud Platform at any point in time.

What should you do?

  1. Use Resource Manager on the organization level.
  2. Use Forseti Security to automate inventory snapshots.
  3. Use Stackdriver to create a dashboard across all projects.
  4. Use Security Command Center to view all assets across the organization.

Answer(s): D



Viewing page 7 of 74
Viewing questions 31 - 35 out of 361 questions



Post your Comments and Discuss Google PROFESSIONAL-CLOUD-SECURITY-ENGINEER exam prep with other Community members:

PROFESSIONAL-CLOUD-SECURITY-ENGINEER Exam Discussions & Posts