[Jul-2023] Professional-Cloud-Security-Engineer Dumps are Available for Instant Access from Actual4Dumps [Q32-Q47]

Share

[Jul-2023] Professional-Cloud-Security-Engineer Dumps are Available for Instant Access from Actual4Dumps

Study resources for the Valid Professional-Cloud-Security-Engineer Braindumps!

NEW QUESTION # 32
When creating a secure container image, which two items should you incorporate into the build if possible?
(Choose two.)

  • A. Use public container images as a base image for the app.
  • B. Remove any unnecessary tools not needed by the app.
  • C. Package a single app as a container.
  • D. Use many container image layers to hide sensitive information.
  • E. Ensure that the app does not run as PID 1.

Answer: B,C

Explanation:
Explanation/Reference: https://cloud.google.com/solutions/best-practices-for-building-containers


NEW QUESTION # 33
A manager wants to start retaining security event logs for 2 years while minimizing costs. You write a filter to select the appropriate log entries.
Where should you export the logs?

  • A. Cloud Pub/Sub topics
  • B. StackDriver logging
  • C. BigQuery datasets
  • D. Cloud Storage buckets

Answer: D


NEW QUESTION # 34
A company is running workloads in a dedicated server room. They must only be accessed from within the private company network. You need to connect to these workloads from Compute Engine instances within a Google Cloud Platform project.
Which two approaches can you take to meet the requirements? (Choose two.)

  • A. Configure the project with Shared VPC.
  • B. Configure all Compute Engine instances with Private Access.
  • C. Configure the project with Cloud Interconnect.
  • D. Configure the project with Cloud VPN.
  • E. Configure the project with VPC peering.

Answer: C,D

Explanation:
Explanation
A) IPsec VPN tunels: https://cloud.google.com/network-connectivity/docs/vpn/concepts/overview Interconnect https://cloud.google.com/network-connectivity/docs/interconnect/concepts/dedicated-overview


NEW QUESTION # 35
Your company is using GSuite and has developed an application meant for internal usage on Google App Engine. You need to make sure that an external user cannot gain access to the application even when an employee's password has been compromised.
What should you do?

  • A. Configure Cloud Identity-Aware Proxy for the App Engine Application.
  • B. Enforce 2-factor authentication in GSuite for all users.
  • C. Configure Cloud VPN between your private network and GCP.
  • D. Provision user passwords using GSuite Password Sync.

Answer: C


NEW QUESTION # 36
You need to connect your organization's on-premises network with an existing Google Cloud environment that includes one Shared VPC with two subnets named Production and Non-Production. You are required to:
Use a private transport link.
Configure access to Google Cloud APIs through private API endpoints originating from on-premises environments.
Ensure that Google Cloud APIs are only consumed via VPC Service Controls.
What should you do?

  • A. 1. Set up a Direct Peering link between the on-premises environment and Google Cloud.
    2. Configure private access for both VPC subnets.
  • B. 1. Set up a Dedicated Interconnect link between the on-premises environment and Google Cloud.
    2. Configure private access using the restricted.googleapis.com domains in on-premises DNS configurations.
  • C. 1. Set up a Cloud VPN link between the on-premises environment and Google Cloud.
    2. Configure private access using the restricted googleapis.com domains in on-premises DNS configurations.
  • D. 1. Set up a Partner Interconnect link between the on-premises environment and Google Cloud.
    2. Configure private access using the private.googleapis.com domains in on-premises DNS configurations.

Answer: A


NEW QUESTION # 37
Your team needs to configure their Google Cloud Platform (GCP) environment so they can centralize the control over networking resources like firewall rules, subnets, and routes. They also have an on-premises environment where resources need access back to the GCP resources through a private VPN connection. The networking resources will need to be controlled by the network security team.
Which type of networking design should your team use to meet these requirements?

  • A. Cloud VPN Gateway between all engineering projects using a hub and spoke model
  • B. VPC peering between all engineering projects using a hub and spoke model
  • C. Grant Compute Admin role to the networking team for each engineering project
  • D. Shared VPC Network with a host project and service projects

Answer: D

Explanation:
Reference:
https://cloud.google.com/docs/enterprise/best-practices-for-enterprise- organizations#centralize_network_control


NEW QUESTION # 38
You are a security administrator at your company. Per Google-recommended best practices, you implemented the domain restricted sharing organization policy to allow only required domains to access your projects. An engineering team is now reporting that users at an external partner outside your organization domain cannot be granted access to the resources in a project. How should you make an exception for your partner's domain while following the stated best practices?

  • A. Turn off the domain restricted sharing organization policy. Set the policy value to "Custom." Add each external partner's Cloud Identity or Google Workspace customer ID as an exception under the
  • B. Turn off the domain restriction sharing organization policy. Set the policy value to "Allow All."
  • C. Turn off the domain restricted sharing organization policy. Add each partner's Google Workspace customer ID to a Google group, add the Google group as an exception under the organization policy, and then turn the policy back on.
  • D. Turn off the domain restricted sharing organization policy. Provide the external partners with the required permissions using Google's Identity and Access Management (IAM) service.

Answer: D

Explanation:
organization policy, and then turn the policy back on.


NEW QUESTION # 39
Your team sets up a Shared VPC Network where project co-vpc-prod is the host project. Your team has configured the firewall rules, subnets, and VPN gateway on the host project. They need to enable Engineering Group A to attach a Compute Engine instance to only the 10.1.1.0/24 subnet.
What should your team grant to Engineering Group A to meet this requirement?

  • A. Compute Shared VPC Admin Role at the service project level.
  • B. Compute Network User Role at the subnet level.
  • C. Compute Shared VPC Admin Role at the host project level.
  • D. Compute Network User Role at the host project level.

Answer: C


NEW QUESTION # 40
A business unit at a multinational corporation signs up for GCP and starts moving workloads into GCP. The business unit creates a Cloud Identity domain with an organizational resource that has hundreds of projects.
Your team becomes aware of this and wants to take over managing permissions and auditing the domain resources.
Which type of access should your team grant to meet this requirement?

  • A. Organization Administrator
  • B. Organization Role Administrator
  • C. Security Reviewer
  • D. Organization Policy Administrator

Answer: B


NEW QUESTION # 41
A customer needs to prevent attackers from hijacking their domain/IP and redirecting users to a malicious site through a man-in-the-middle attack.
Which solution should this customer use?

  • A. Cloud Identity-Aware Proxy
  • B. Cloud Armor
  • C. VPC Flow Logs
  • D. DNS Security Extensions

Answer: D

Explanation:
Explanation/Reference: https://cloud.google.com/blog/products/gcp/dnssec-now-available-in-cloud-dns


NEW QUESTION # 42
You need to enable VPC Service Controls and allow changes to perimeters in existing environments without preventing access to resources. Which VPC Service Controls mode should you use?

  • A. Dry run
  • B. Cloud Run
  • C. Native
  • D. Enforced

Answer: A


NEW QUESTION # 43
A large financial institution is moving its Big Data analytics to Google Cloud Platform. They want to have maximum control over the encryption process of data stored at rest in BigQuery.
What technique should the institution use?

  • A. Use Cloud Storage as a federated Data Source.
  • B. Use a Cloud Hardware Security Module (Cloud HSM).
  • C. Customer-managed encryption keys (CMEK).
  • D. Customer-supplied encryption keys (CSEK).

Answer: C

Explanation:
https://cloud.google.com/bigquery/docs/encryption-at-rest


NEW QUESTION # 44
Your security team uses encryption keys to ensure confidentiality of user dat a. You want to establish a process to reduce the impact of a potentially compromised symmetric encryption key in Cloud Key Management Service (Cloud KMS).
Which steps should your team take before an incident occurs? (Choose two.)

  • A. Limit the number of messages encrypted with each key version.
  • B. Disable and revoke access to compromised keys.
  • C. Manually rotate key versions on an ad hoc schedule.
  • D. Enable automatic key version rotation on a regular schedule.
  • E. Disable the Cloud KMS API.

Answer: B,D


NEW QUESTION # 45
You want to make sure that your organization's Cloud Storage buckets cannot have data publicly available to the internet. You want to enforce this across all Cloud Storage buckets. What should you do?

  • A. Remove Owner roles from end users, and enforce domain restricted sharing in an organization policy.
  • B. Remove Owner roles from end users, and configure Cloud Data Loss Prevention.
  • C. Remove *.setIamPolicy permissions from all roles, and enforce domain restricted sharing in an organization policy.
  • D. Configure uniform bucket-level access, and enforce domain restricted sharing in an organization policy.

Answer: D


NEW QUESTION # 46
Your company requires the security and network engineering teams to identify all network anomalies within and across VPCs, internal traffic from VMs to VMs, traffic between end locations on the internet and VMs, and traffic between VMs to Google Cloud services in production. Which method should you use?

  • A. Enable VPC Flow Logs on the subnet.
  • B. Configure packet mirroring policies.
  • C. Monitor and analyze Cloud Audit Logs.
  • D. Define an organization policy constraint.

Answer: A


NEW QUESTION # 47
......


Google Professional-Cloud-Security-Engineer (Google Cloud Certified - Professional Cloud Security Engineer) Certification Exam is a rigorous and comprehensive assessment designed to test the skills and knowledge of individuals who are interested in becoming certified Google cloud security professionals. Google Cloud Certified - Professional Cloud Security Engineer Exam certification exam is created by Google Cloud, which is one of the leading providers of cloud computing services in the world.

 

Updated Professional-Cloud-Security-Engineer Tests Engine pdf - All Free Dumps Guaranteed: https://www.actual4dumps.com/Professional-Cloud-Security-Engineer-study-material.html

Latest Google Cloud Certified Professional-Cloud-Security-Engineer Actual Free Exam Questions: https://drive.google.com/open?id=15ksIJF_xkkPRFs3-FzG6M7z2n5s05ZYG