All questions

Google Cloud Professional Cloud Security Engineer Practice Exam

Browse all practice questions for the Google Cloud Professional Cloud Security Engineer Practice Exam. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Google Cloud Professional Cloud Security Engineer Practice Exam 2026 – All-in-One Comprehensive Study Guide for Success! course image
A Closer Look at Access Issues with Cloud Storage Buckets and CMEKWhy might you encounter access issues when creating a Cloud Storage bucket using a customer managed encryption key (CMEK) from a different project?Accessing Google Drive on Behalf of Users: Best PracticesWhat is the best practice to access a user's Google Drive on their behalf in an App Engine application?Capturing VPC Traffic: Why Packet Mirroring is Your Best BetWhich feature should be utilized to capture VPC traffic for analysis without missing significant events?Enhancing Security in DevOps with Infrastructure as CodeTo enable developer teams to deploy applications without a full network and security review, what should the organization mandate?Ensuring Secure Communication Between GCP and On-Premises EnvironmentsWhat should be configured to ensure secure communication between GCP and on-premises environments?Ensuring Trusted Operating System Images in Google Cloud ProjectsWhat organizational policy can ensure that only trusted operating system images are used in Google Cloud projects?Essential Steps for Integrating On-Premises Active Directory with Google CloudWhat two steps should be taken to integrate on-premises Active Directory with Google Cloud?Finding the Right IAM Design for BigQuery ReportsWhich IAM design is appropriate for a business user who must access curated reports in BigQuery?How a Hierarchical Firewall Policy Can Secure Your MySQL Port AccessWhen using Security Command Center Premium, what is a recommended action to prevent misconfigurations related to MySQL port access?How to Anonymize Sensitive Health Information with Google Cloud SolutionsTo anonymize sensitive health information in a reversible way, which Google Cloud solution is appropriate?How to Effectively Obfuscate Dates in BigQuery without Losing Data IntegrityWhat method should be used to obfuscate start and end dates while preserving interval data in BigQuery?Locking Down Your Compute Engine: Ensuring No Internet AccessWhat is one strategy to ensure that a Compute Engine instance cannot access the internet while processing data?Master Access Control with Cloud Identity-Aware Proxy for Google App EngineWhat solution should be implemented to restrict access to in-progress websites hosted on App Engine?Mastering Access Control in Google Cloud StorageWhat configuration allows you to manage access for a Cloud Storage bucket with many objects without managing each individually?Mastering Cloud Security: Securing Your Google Cloud Storage BucketsTo ensure Cloud Storage buckets are not publicly accessible, which configuration should be enforced?Mastering Cloud Security: The Importance of Security KeysWhat security measure is recommended to prevent person-in-the-middle attacks in a Google Cloud environment?Mastering Customer-Managed Encryption Keys on Google CloudWhat command can you execute to enforce customer-managed encryption keys (CMEK) for all new Cloud Storage resources?Mastering Data Encryption in Google Cloud Storage: Your Key to ComplianceWhat should be done to use a key generated on-premises for data encryption in Cloud Storage?Mastering Data Protection in Google Cloud StorageWhat is the best approach to protect sensitive data in a Cloud Storage bucket that can only be read from another project?Mastering Data Residency with Google Cloud's Secret ManagerWhat is the best way to ensure the payloads of secrets in Google Cloud's Secret Manager are compliant with data residency requirements?Mastering Envelope Encryption: Your Guide to Data SecurityWhich steps are involved in encrypting data using envelope encryption?Mastering Google Cloud Identity-Aware Proxy Roles for Secure AccessWhich Identity-Aware Proxy role is necessary for an IAM user to access HTTPS resources?Mastering Google Cloud Monitoring: Why Cloud Pub/Sub Is Your Best BetWhat should be used for monitoring the "implementation" folder for project additions in the GCP environment?Mastering Google Cloud OS Image RestrictionsWhat role should be granted to ensure that all VMs in a Google Cloud organization can only use a specific OS image while minimizing operational overhead?Mastering Google Cloud Security Assets with Security Command CenterWhat solution provides a historical record of all assets in Google Cloud Platform?Mastering Google Cloud Security: Granting Access with ExpertiseWhat is the best approach to give Project B access to a Pub/Sub topic in Project A while adhering to least privilege?Mastering Google Cloud Security: The Role of External HTTP(S) Load BalancersTo minimize internet exposure for Google Cloud VMs that host web services, what should you implement?Mastering Google Cloud: Controlling Service Account CreationTo restrict service account creation capability in production environments centrally, what should be implemented?Mastering IAM Access Reviews with Policy AnalyzerWhat tool is recommended to provide access reviews evidence for IAM?Mastering IAM Permissions for KMS Keys in Google CloudHow should IAM permissions for KMS keys be managed for Compute Engine disks?Mastering IAM Roles: Granting Access to Security LogsWhich IAM role should be granted to provide view access to security-related logs while adhering to least privilege principles?Mastering IP Packet Inspection with Google CloudHow can you inspect IP packet data for invalid or malicious content effectively?Mastering Key Management on Google Cloud: A Secure ApproachWhat encryption solution can be recommended to clients wanting to manage their own encryption keys securely?Mastering Migration Security: G Suite's Built-In BenefitsWhich solution ensures that network security controls are maintained when migrating to G Suite?Mastering Network Abnormality Detection in Google Cloud's VPCsWhat method should be implemented to identify network abnormalities and capture payloads within VPCs?Mastering PII Deletion in Google CloudWhat is the recommended method for deleting personally identifiable information (PII) on Google Cloud?Mastering Resource Auditing in Google CloudWhat method should be used to audit new resources created by a compromised service account?Mastering Security Perimeters in Google CloudHow can you set up a security perimeter to prevent data exfiltration while allowing project communication?Mastering Sensitive Data Encryption in Google CloudHow should sensitive data encryption requirements be met when using Google Cloud?Mastering Service Account Key Management in Google CloudWhat method should be used to prevent developers from creating user-managed service account keys in Google Cloud?Mastering SSO Implementation with SAML in Active DirectoryWhich steps are necessary for implementing SSO with SAML in an Active Directory environment?Mastering the Container Update Process in Google Kubernetes EngineWhat is the recommended process to update running containers in Google Kubernetes Engine?Mastering the Essentials: Public IP Restrictions in Google CloudWhat method should be used to enforce that Compute Engine instances in production do not have public IPs?Mastering Two-Factor Authentication with Google Cloud Identity-Aware ProxyWhich GCP product should be used to provide a two-factor authentication layer for a CRM accessed over the internet?Mastering VPC Service Controls Updates without DisruptionWhat is the recommended approach to update a VPC Service Controls perimeter without disrupting existing access?Mastering VPC Service Controls: The Power of Dry Run ModeWhat mode should you use in VPC Service Controls to make changes to perimeters without blocking resource access?Mastering Web Security with Google Cloud: Understanding XSS AttacksWhat tool can be used to simulate an XSS injection attack on a web application in GKE?Maximizing Certificate Management Efficiency with Google CloudIf your organization has an on-premises PKI system and needs to scale certificate issuance for HTTP load balancers, what is a viable solution?Navigating Google Cloud Authentication with Third-Party SSO SAMLWhat two options are necessary to authenticate using a third-party SSO SAML identity provider with gcloud?Navigating IAM Permissions: The Power of Cloud Directory SyncWhat tool allows for smooth management of IAM permissions from an on-premises system?Navigating Identity Management in Hybrid Cloud EnvironmentsWhich configuration can help apply consistent identity management across hybrid environments with on-premises Active Directory?Restricting Access: A Key Focus on Google Cloud Resources SecurityWhat is a key focus when implementing security measures on Google Cloud resources?Routing Customers to the Nearest Mail Server Made EasyWhat should a company implement to route customers to the nearest mail server based on location?Secure Your Cloud API Access: The Best Configuration for On-Premises ApplicationsWhat configuration should be used to ensure that on-premises applications only access Google APIs through Cloud Interconnect?Securing Your Private VMs: The Magic of Tailored Firewall RulesWhat can be done to reduce the risk of external access to private VMs?Storing Sensitive Configuration Data: Google Cloud's Secret Manager ExplainedWhat is the recommended solution for storing sensitive configuration data from a Compute Engine application?Strengthening Google Cloud Account Security with 2-Step VerificationTo reduce the risk of Google Cloud account compromise, what should be configured after SSO?The Importance of Packet Mirroring in Google Cloud SecurityWhen implementing cloud security measures, what aspect is crucial for monitoring and auditing network activity?The Importance of Password Length in Cloud SecurityWhat is the minimum password length guideline for Cloud Identity accounts as per the organization's requirements?The Key to Synchronizing User Changes in Google CloudWhat should be used to regularly replicate user changes from an on-premises LDAP server to Google Cloud resources?The Smart Way to Keep Your Windows VMs Up to Date with OS PatchesWhat is the best approach for ensuring Windows Compute Engine VMs are up to date with OS patches?Understanding Access Control in Google Cloud’s "Apps" FolderWhat action results in a failure when trying to grant access to a project in the "Apps" folder?Understanding Google Shielded VMs: Your Best Defense Against Boot-Level MalwareWhat Google Cloud feature is essential for protecting sensitive workloads from boot-level malware?Understanding Shared Security Responsibilities in IaaSIn a shared security responsibility model for IaaS, which two layers does the customer share responsibility for?Understanding the Binary Authorization Policy in Google CloudWhat is the function of the Binary Authorization policy in Google Cloud?Understanding the Cloud Data Loss Prevention API for Tokenization in BigQueryWhich API should be used for tokenization and pseudonymization in BigQuery?Understanding the Importance of Customer Managed Encryption Keys in Google Cloud SecurityIf your organization requires Customer Managed Encryption Keys (CMEK), what should you do with existing files stored using Google Managed Encryption Keys (GMEK)?Understanding the OS Config Agent for Effective VM PatchingWhat is the role of the OS Config agent in managing VM patching?Understanding the Transfer Tool for Unmanaged Users in Google CloudWhat is the purpose of the Transfer Tool for Unmanaged Users (TTUU)?Understanding VPC Firewall Rules: The Role of Network Tags in Google CloudWhat is a likely reason for VM instances being able to communicate freely despite existing VPC firewall rules?Understanding VPC Peering in Google CloudWhich characteristic is true about VPC peering?Why Configuring an Identity-Aware Proxy is Key for Your Google Cloud SecurityWhat is the purpose of configuring an Identity-Aware Proxy (IAP) in Google Cloud?Why Running CI/CD Pipelines in Separate Namespaces MattersWhen creating the CI/CD pipelines, why is it important to run them in separate namespaces?Why Two VPC Networks are Your Best Bet for Cloud SecurityWhat is the recommended network design to inspect traffic between untrusted and trusted segments with a next-generation firewall?Why Understanding the Policy Analyzer is Key for IAM SuccessWhich feature can provide guidance on permissions for specific actions in IAM?
More practice questions

These questions are part of the practice quiz. Start practicing

  • What is the benefit of using Google's Cloud Identity-Aware Proxy?
  • Which method is appropriate for ensuring that manually created users in Google Cloud are disabled during LDAP synchronization?
  • How should access control permissions be managed in an organization with many business units?
  • Which type of load balancer is recommended to maintain client IP while using the standard network tier?
  • How can an organization ensure that customer data at rest adheres to specific geographic boundaries on Google Cloud?
  • What approach should be taken to ensure only trusted container images are deployed on Cloud Run?
  • Which solution allows you to centralize logs from production projects for analysis in Google Cloud?
  • If a user loses their second factor for 2-Step Verification, what is the best immediate action to take?
  • What should be done to ensure credit card numbers are not stored in BigQuery?
  • What is the benefit of using customer-managed encryption keys for secrets in Secret Manager?
  • What type of access should your team grant to manage permissions and audit domain resources within a Cloud Identity domain?
  • What is the primary purpose of installing VM Manager on virtual machines in a Google Cloud environment?
  • What two actions should a company take to manage IAM permissions between users in development and production environments? (Choose two.)
  • What is a suitable solution for backing up application logs while restricting PII access to analysts?
  • Which product should be used for DDoS protection while meeting compliance requirements for known good CIDR traffic?
  • Which Google Cloud service should be used to authenticate responses to domain name lookups following DDoS attacks?
  • To evaluate only relevant controls against CIS Google Cloud Computing Foundations, what should be done?
  • What action should you take to set up a single external IP for distributing requests across multiple regions?
  • Which load balancer types are denied at the global node's policy in a resource hierarchy?
  • Before migrating Google Cloud projects to a new organization node, which steps are necessary?
  • To ensure in-scope PCI Kubernetes Pods only reside on specific nodes, how should this be configured?
  • How should you configure access to Google APIs over Cloud Interconnect to mitigate exfiltration risk?
  • How should a VPC be configured to allow the security team to manage firewall rules while designing separation of duties?
  • To avoid giving the uploader of an object full control while managing bucket access, what should be enabled?
  • What should be the configuration for Pods that need to avoid being scheduled on non-in-scope Nodes?
  • What is the first step in creating a governance model for storing secrets in Secret Manager?
  • Which Google Cloud service helps ensure uploaded user comments do not include sensitive data?
  • To ensure secure connectivity between on-premises and Google Cloud applications, which method is recommended for transferring data at high bandwidth?
  • Which service is best for managing symmetric encryption keys for Cloud Dataproc persistent disks?
  • When assessing external IP address usage, which practice is recommended for optimal security posture?
  • When investigating public access incidents in Cloud Storage buckets, what immediate actions should be taken?
  • What should be done after a service account is accidentally deleted to recover application functionality quickly?
  • What is the best approach to get notified if an application bug reoccurs in Compute Engine?
  • In the context of secure application deployments, what is the recommended frequency for updating and reviewing security policies?
  • What is the most suitable solution for deploying workloads while ensuring compliance with data residency regulations?
  • To follow Google-recommended best practices while deploying a CI/CD pipeline, what action should be taken regarding default networks?
  • Which Cloud Data Loss Prevention API technique is best for tracking changes in bonus compensation without exposing individual data?
  • Which encryption strategy is suitable for managing sensitive and non-sensitive data compliance?
  • How can you enhance network security in a Google Cloud VPC for autoscaling services?
  • Which Cloud Data Loss Prevention API technique should be used to track compensation over time while keeping individual data secure?
  • What is the best method to ensure compliance with FIPS 140-2 for a messaging app using GCP services?
  • Which Google Cloud product should you utilize to explore network traffic using payloads and headers?
  • In order to comply with data retention regulations for instance logging within Europe, what is the correct configuration approach?
  • What is the recommended approach for managing encryption keys when migrating an application to the cloud under strict regulatory requirements?
  • How can you ensure personally identifiable information (PII) shared during online chat is not stored in chat logs?
  • What is the ideal way to ensure control over consumer accounts that use corporate email addresses?
  • Which actions are necessary to meet a seven-year data retention policy in Cloud Storage?
  • When defining access for a DevOps team to troubleshoot deployment issues, what access strategy should be employed?
  • What should be implemented to protect employee credentials from phishing?
  • What feature can be used to control access to a GCP environment for certain resources?
  • If a leadership team is concerned about internal employee access to sensitive data on Google Cloud, what should be proposed?
  • Which strategy can be effectively used in a CI/CD pipeline for maintaining application integrity?
  • What type of vulnerabilities must a scanning solution for Kubernetes Engine be able to detect?
  • What is the best practice for ensuring sensitive user data protection in a development environment?
  • What action is appropriate to reduce the risk of cookie replay attacks on Google Cloud?
  • What is a necessary step to generate provenance for software builds to assure they are untampered?
  • In transitioning to Google Cloud, what is essential for ensuring only trusted containers are deployed?
  • What is the purpose of implementing an Access Policy in BeyondCorp Enterprise?
  • Which solution should a customer use to prevent attackers from hijacking their domain/IP and redirecting users to a malicious site through a man-in-the-middle attack?
  • What is the benefit of using Cloud Data Loss Prevention (DLP) within a Cloud Storage solution?
  • What must be done to ensure your encryption keys are rotated within the specified timeframe?
  • How can you quickly perform compliance reporting for VMs lacking critical OS security updates?
  • Which connectivity option is suitable for ensuring that communication between different application tiers does not traverse the public internet?
  • To leverage envelope encryption and encrypt data at the application layer, what is the recommended approach?
  • What policy constraint can help prevent the accidental deletion of a Shared VPC host project?
  • What key management practices must be followed when migrating to BigQuery and other services?
  • Which requirement must be met when using Google Cloud Armor security policies?
  • To troubleshoot firewall rule issues suspected of causing application outages, what action should be taken?
  • Which Google Cloud service provides external web application protection against common attacks?
  • What is the best method to securely store plain text secrets in Google Cloud Platform?
  • What is an effective way to reduce the scope of PCI audit standards within GCP?
  • How can you prevent unauthorized access from unattended employee laptops in Google Cloud?
  • What configuration is necessary for routing internet traffic securely through an on-premises connection?
  • How can application teams be restricted to adding only internal users to their Google Cloud groups?
  • What is the primary method to identify network anomalies across VPCs in Google Cloud?
  • Why should organizations implement row-level access policies in BigQuery?
  • When granting IAM roles for audit log access in different application environments, what should you do for the developers?
  • What should the permissions for the general service account enable it to do?
  • To automate data deletion after a specific retention period, what feature should you use in Cloud Storage?
  • When you need to shield sensitive data from unauthorized access in log files, what approach should you take?
  • To prevent any VM from reaching the public internet while performing batch processing, what should be enabled?
  • In a scenario where logs need PII detection, what is a practical approach to handle it?
  • To export security logs for Google Cloud, which two actions are necessary?
  • What is required to ensure proper API access from an on-premises environment to Google Cloud APIs?
  • To centrally manage GCP IAM permissions based on Active Directory group membership, what should your team do?
  • What defines the members allowed to access resources in an organization node in Google Cloud?
  • How can you validate that data written to BigQuery was done using the App Engine Default Service Account?
  • What permission is needed for Engineering Group A to attach a Compute Engine instance to a specific subnet in Shared VPC?
  • What solution should be recommended to reduce the need for public IP addresses in customer VMs?
  • How can you minimize the risk associated with long open Google Cloud CLI sessions?
  • What two actions should be taken to securely configure communication between Web and App servers on Google Cloud?
  • What elements must be considered when implementing data residency requirements for a CISO?
  • At which level in the resource hierarchy should you set the Resource Location Restriction organization policy constraint?
  • Which port is the administrative application running on in the provided scenario?
  • To perform a quick security audit of publicly exposed network assets, what is the most efficient initial step?
  • What scanning solution should be used for an application deployed on Google Kubernetes Engine to detect vulnerabilities?
  • What are two best practices when configuring authentication and authorization in Google Cloud?
  • To protect sensitive health information within VMs, what should be enforced organization-wide?
  • In the context of Google Cloud security, what is a service perimeter?
  • Which Google Cloud solution allows for managing encryption keys that must be stored in multiple regions for redundancy?
  • If a service account key has been compromised, what should be the immediate action to secure access?
  • How can you enforce network security while using VPC peering?
  • In order to securely track compensations while preventing data exposure, what must be maintained?
  • To ensure end-to-end encryption of application data in Google Cloud, which two options should be utilized?
  • What is the best GCP solution for migrating ongoing data backup and disaster recovery solutions?
  • Which logging export strategy meets the requirement for a unified log view in SIEM from development projects?
  • For preserving logs for 12 years within European boundaries, which solution is recommended?
  • How can you ensure the sensitive data's encryption key is managed outside of Google Cloud?
  • Which Google Cloud service enables VM instances without external IP addresses to connect to the internet?
  • When your organization seeks full control over encryption keys used for data at rest, what approach should be taken?
  • How can a team ensure that only the frontend application can access the backend database?
  • Which service should be utilized to enforce access control policies for applications in Google Cloud?
  • Which identity management solution is best for managing permissions across various business units?
  • Which Google Cloud product helps detect overlapping firewall rules based on priorities?
  • Which Security Command Center feature should be enabled to configure alerts for potential crypto mining and common Google Cloud misconfigurations impacting security?
  • What is the first step to implement Workload Identity Federation (WIF) with an on-premises identity provider?
  • What is the essential feature of Google Cloud IAM?
  • Which role is essential to grant the security operations team for effective log management?
  • For real-time audit log exports in Google Cloud, which mechanism should be used?
  • What can be done to ensure trusted operating system images in Google Cloud projects?
  • Why is it important to monitor Data Access audit logs?
  • What is a primary benefit of using customer-managed encryption keys over Google-managed keys?
  • What action must be performed to modify access to the VM running in a managed group?
  • For data confidentiality, what encryption method is recommended for communication between Compute Engine instances?
  • What is the recommended solution for managing identities when using GCP along with an established directory service?
  • What is the best approach to prevent the deployment of containers with known vulnerabilities in a CI/CD pipeline on GKE?
  • Which command allows you to recover a deleted service account quickly?
  • What is the purpose of an access binding with an access policy in BeyondCorp Enterprise?
  • Which method helps ensure compliance with GDPR in Google Cloud by limiting where resources are physically located?
  • Which organization policy constraint affects granting access to the "Apps" folder?
  • What solution should a team implement to avoid exposing a public web application directly on the internet while blocking malicious IPs?
  • What should be created to execute batch jobs with specific permissions?
  • What feature of Google Cloud ensures secure access to applications running on VMs?
  • For compliance reasons, which two IAM roles should an office manager have to manage billing tasks?
  • Which practice minimizes operational overhead while implementing crypto-shredding for PII?
  • Which Google Cloud tool can help identify and alert on application vulnerabilities?
  • When synchronizing users with Google Cloud Directory Sync (GCDS), what should you do for users already with Google Cloud accounts?
  • What Google Cloud feature can be used to ensure data integrity and security on Compute Engine VMs?
  • What is the most secure way to allow CI/CD pipelines access to Google Cloud resources?
  • To limit traffic from suspicious IP addresses to your global HTTP(S) load balancer, what should you configure?
  • Which role should a user have to perform security audits across all projects within an organization?
  • What should be done immediately after identifying vulnerable Google Cloud CLI sessions?
  • Which option ensures that a Compute Engine instance can read data from a Cloud Storage bucket while adhering to the principle of least privilege?
  • Which type of logs should be analyzed to detect possible intrusions when using Identity-Aware Proxy (IAP)?
  • What practice should be followed to perform static analysis of code during deployment?
  • How should a Systems Engineer proceed when a customer's domain is already being used by G Suite, preventing the setup of Cloud Identity?
  • What should an organization do to maintain compliance with security policies regarding data access?
  • What Google 2-Step Verification (2SV) option should be used for cryptographic signature authentication?
  • For a bursty workload with key lifecycle control in Compute Engine, which encryption solution is recommended?
  • What principle should guide the access concept design for batch jobs in Google Cloud?
  • Which logs should a database administrator review to monitor malicious activities in a Cloud SQL instance?
  • What is a benefit of using the Cloud Data Loss Prevention API?
  • In a CI/CD pipeline context, what is the likely consequence of not utilizing organization policy constraints effectively?
  • How can user access in BigQuery be limited effectively during specified hours?
  • What is the recommended method to securely access private VMs remotely on Google Cloud?
  • How can you enforce egress traffic restrictions on a folder level in Google Cloud?
  • Which Google Cloud product allows for exploration of network flows and their payload to aid investigations?
  • How should you address encryption-at-rest for sensitive data while minimizing key management complexity?
  • What is the best way for a customer to reliably deliver Stackdriver logs from GCP to their on-premises SIEM system?
  • What service should be used to check for Open Web Application Security Project (OWASP) vulnerabilities in an application deployed on App Engine?
  • What is the recommended way to create a Service Account for listing Compute Engine instances in a project?
  • Which two components should be utilized to redact personally identifiable information during ETL processes?
  • What type of encryption key should be managed for workloads in Compute Engine, Google Kubernetes Engine, Cloud Storage, BigQuery, and Pub/Sub in compliance with GDPR?
  • In order to prevent data exfiltration from BigQuery containing PII, what security measure should be applied?
  • What primary concern should be adhered to when granting permissions to batch jobs?
  • Which two roles should be restricted to limit users with administrative privileges at the organization level?
  • Which Google Cloud solution is recommended for migrating data backup and disaster recovery solutions for analysis?
  • To ensure GDPR compliance for resource creation, what should be applied to the Google Cloud organization?
  • How can data be protected when using Google Cloud services that involve sensitive data?
  • What is a crucial benefit to using workload identity federation with GitHub for CI/CD integrations?
  • What is the first step for conducting security scanning of container images in Google Cloud?
  • Which international compliance standard provides cloud services information security controls?
  • What should be done to ensure environment separation between Production and Non-Production secrets?
  • How can you ensure compliance with specified data storage duration for cloud backups?
  • To automatically grant read-only access to all department members for new projects, what is the recommended configuration?
  • What is the recommended first step to convert unmanaged Google accounts to managed accounts?
  • How should you allow an external partner's domain access to your Google Cloud project while adhering to best practices?
  • What is one approach to manage traffic rules effectively in your Google Cloud environment?
  • Where is the best place to export security event logs for retention for 2 years while minimizing costs?
  • What is the primary purpose of Google Cloud Directory Sync?
  • When building secure container images, what should be removed?
  • If your organization enforces a minimum data retention period for records, which Google service would you use?
  • To minimize credential theft for a CI/CD cluster deployed on Compute Engine, what should be implemented?
  • What feature should be used to manage user access to an application remotely?
  • When creating a Google Cloud organization, how can you enhance security for super administrator accounts?
  • When troubleshooting VPC access, what is a recommended first step to check permissions related to datasets?
  • Which feature of Google Cloud can help to prevent unauthorized queries to BigQuery tables?
  • What is the recommended method for handling logs with personally identifiable information in Cloud Storage?
  • Which method must be used to connect on-premises networks to Google Cloud while ensuring secure access to Google APIs?
  • To secure communication between two separate Google Cloud organization's Compute Engine instances, what configuration should be used?
  • When implementing the principle of least privilege, what is the main consideration in granting permissions?
  • What should be done after creating a key in the external key management partner system for BigQuery encryption?
  • What is the main purpose of using Cloud External Key Manager in Google Cloud?
  • How can you organize Google Cloud projects based on independent business units while maintaining IAM permissions?
  • What proactive measure can you implement to prevent external exposure of objects in Google Cloud buckets?
  • What action should be taken to allow Compute Engine instances limited internet access while reaching out for security updates?
  • To centralize control over networking resources while connecting to an on-premises environment, what Google Cloud design should be used?
  • Which practices help reduce the impact of a compromised symmetric encryption key in Cloud KMS?
  • What is essential to control when managing Cloud KMS key access?
  • To ensure all virtual machines in your organization encrypt sensitive health data while in use, what policy is necessary?
  • What should an organization do to maintain compliance when operating workloads in specific geographical regions?
  • Which service can ensure that data in Cloud Storage is only accessible within the defined projects?
  • Which Google Cloud service is primarily utilized to protect applications as part of a zero trust model?
  • How can your team restrict project creation within an organization?
  • What is the first step to using Cloud External Key Manager for encrypting BigQuery data at rest?
  • What is necessary before migrating sensitive project data to a different Google Cloud organization?
  • What should be done with consumer user accounts created with a corporate domain name when onboarding into Cloud Identity?
  • How can a team manage customer-supplied encryption keys (CSEK) for Cloud Storage?
  • What action should be taken to confirm unauthorized access to Google Cloud resources by a former employee?
  • In a CI/CD workflow on Google Kubernetes Engine, what is the recommended approach for securely accessing Google Cloud APIs?
  • To synchronize security groups that include email addresses from an LDAP directory, which tool should be configured?
  • What action should be taken if encountering an error with log sinks and uniform bucket-level access in Cloud Storage?
  • What is the primary purpose of creating a log sink at the organization level in Google Cloud?
  • What method can improve the security of data stored in GCP from unauthorized access?
  • What is a benefit of using Cloud Armor for web applications?
  • Which option is best to configure to restrict unauthorized access to Google Cloud resources?
  • Which tool provides a mechanism to manage the lifecycle of cryptographic keys effectively?
  • To optimize Cloud DLP usage in BigQuery, which resources' cost should be limited?
  • Which method is recommended for managing access to resources across projects?
  • What must be included in the configuration of a SAML profile for setting up SSO?
  • What should be configured to allow only specific VM communication on a particular port within a VPC?
  • When using App Engine, which area should security and risk management teams focus on as their primary responsibility?
  • In a shared VPC, what is essential for managing network traffic effectively?
  • To ensure that the ERP system only accepts traffic from Cloud Identity-Aware Proxy, what should be done?
  • Which of the following options is a relevant requirement for logging access management in Google Cloud?
  • Which component is used to expose the administrative application running on a VM to users securely?
  • How can you identify all principals who can change firewall rules in Google Cloud?
  • What is the key benefit of using Cloud KMS for managing encryption keys?
  • In a troubleshooting scenario, what is vital to ensure logs meet compliance and security standards?
  • How should a customer automatically deprovision an engineer’s Google account after termination?
  • What is the recommended practice for rotating a user-managed Service Account key in Google Cloud?
  • Which encryption service is recommended for managing encrypted keys that requires FIPS 140-2 Level 3 validation?
  • Which of the following is true about IAM permissions in GCP?
  • Which Google Cloud service allows for secure routing of external traffic to backend services?
  • What is the main method to limit the images used as sources for boot disks in a dedicated project?
  • How can authenticated network separation be achieved for different tiers of a 3-tier web application on Compute Engine?
  • To automate patch management in virtual machines, which two actions should you take?
  • Which two limits can be set to optimize costs when using the Cloud DLP API?
  • To optimize responsiveness, which virtual machine configuration should be considered?
  • Which principle is crucial when defining a deployment issue access strategy?
  • How can you restrict access from a managed instance group front end to a MySQL VM on a specific port?
  • To ensure only authorized users can access an organization's Cloud Storage, what is a relevant policy to implement?
  • Which Google Cloud resource provides web interface access to applications on a VM?
  • What must you do to troubleshoot access denied errors with BigQuery datasets protected by VPC Service Controls?
  • To ensure users can only access data in BigQuery during working hours, what should be implemented?
  • What kind of encryption should be used for directly storing secrets in Google Cloud?
  • Which Security Command Center service should be utilized to detect instances of cryptocurrency mining software?
  • Which step is necessary after enabling Google Cloud Directory Sync (GCDS) for managing users from an on-premises LDAP server?
  • What should be established to promote effective team collaboration whilst maintaining security in a Shared VPC?
  • What steps must be taken to provide access to a third-party disk image secured in an external Google Cloud organization?
  • How can you provide public access to a Linux bastion host without exposing it to external threats?
  • Which document should you review to identify Google's inherent controls for PCI compliance?
  • What action should be taken to remove personally identifiable information (PII) from files older than 12 months stored in Cloud Storage?
  • Which cryptographic token format is recommended for addressing sensitive data exposure while maintaining referential integrity?
  • What might cause an alert regarding an external IP address on a VM after setting an organizational policy to deny their assignment?
  • To achieve compliance and protection for sensitive logs, what should be used with Cloud Functions?
  • To maintain private connectivity and minimize costs for on-premises hosts accessing Google Cloud APIs, what is the recommended solution?
  • What action should be taken to validate security policy changes before enforcement?
  • What is a recommended practice for allowing cloud personnel access based on geography?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy