
Start your Professional-Cloud-Security-Engineer Exam Questions Preparation with Updated 178 Questions
A Fully Updated 2023 Professional-Cloud-Security-Engineer Exam Dumps - PDF Questions and Testing Engine
The Google Cloud Certified - Professional Cloud Security Engineer Exam certification validates the knowledge and skills required to design, implement and manage security solutions in Google Cloud. Google Cloud Certified - Professional Cloud Security Engineer Exam certification exam covers various topics, including security policies and procedures, identity and access management, network security, data security, security controls, application security, and incident management. Professional-Cloud-Security-Engineer exam format consists of multiple-choice questions and performance-based scenarios, and candidates are expected to demonstrate practical knowledge and experience in securing Google Cloud infrastructure.
NEW QUESTION # 80
A customer needs to rely on their existing user directory with the requirements of native authentication against it when developing for Google Cloud Platform (GCP). They want to leverage their existing tooling and functionality to gather insight on user activity from a familiar interface. Which action should you take to meet the customer's requirements?
- A. Configure a third-party IdP (Octa or Ping Federate) to manage authentication.
- B. Provision users into Cloud Identity using Just-in-Time SAML 2.0 user provisioning with the customer User Directory as source.
- C. Configure Cloud Identity as a SAML 2.0 Service Provider, using the customer's User Directory as the Identity Provider.
- D. Configure and enforce 2-Step Verification in Cloud Identity for all Super Admins.
Answer: C
Explanation:
A is not correct because client wants to continue using their existing directory.
B is correct because it lets client use their current user directory as source of truth and to be authenticated against while using Cloud identity as their SAML broker.
C is not correct because it adds a protection to super admin account but doesn't address the use case.
D is not correct because it proposes a non-native solution and doesn't address the use case.
https://cloud.google.com/blog/products/identity-security/using-your-existing-identity-management- system-with-google-cloud-platform
https://support.google.com/a/answer/60224
NEW QUESTION # 81
You are in charge of migrating a legacy application from your company datacenters to GCP before the current maintenance contract expires. You do not know what ports the application is using and no documentation is available for you to check. You want to complete the migration without putting your environment at risk.
What should you do?
- A. Migrate the application into an isolated project using a "Lift & Shift" approach in a custom network. Disable all traffic within the VPC and look at the Firewall logs to determine what traffic should be allowed for the application to work properly.
- B. Refactor the application into a micro-services architecture in a GKE cluster. Disable all traffic from outside the cluster using Firewall Rules. Use VPC Flow logs to determine what traffic should be allowed for the application to work properly.
- C. Migrate the application into an isolated project using a "Lift & Shift" approach. Enable all internal TCP traffic using VPC Firewall rules. Use VPC Flow logs to determine what traffic should be allowed for the application to work properly.
- D. Refactor the application into a micro-services architecture hosted in Cloud Functions in an isolated project.Disable all traffic from outside your project using Firewall Rules. Use VPC Flow logs to determine what traffic should be allowed for the application to work properly.
Answer: C
NEW QUESTION # 82
You need to audit the network segmentation for your Google Cloud footprint. You currently operate Production and Non-Production infrastructure-as-a-service (IaaS) environments. All your VM instances are deployed without any service account customization.
After observing the traffic in your custom network, you notice that all instances can communicate freely - despite tag-based VPC firewall rules in place to segment traffic properly - with a priority of 1000. What are the most likely reasons for this behavior?
- A. All VM instances are residing in the same network subnet.
- B. All VM instances are configured with the same network route.
- C. A VPC firewall rule is allowing traffic between source/targets based on the same service account with priority 1001.
- D. All VM instances are missing the respective network tags.
- E. A VPC firewall rule is allowing traffic between source/targets based on the same service account with priority 999.
Answer: D,E
NEW QUESTION # 83
You are in charge of migrating a legacy application from your company datacenters to GCP before the current maintenance contract expires. You do not know what ports the application is using and no documentation is available for you to check. You want to complete the migration without putting your environment at risk.
What should you do?
- A. Migrate the application into an isolated project using a "Lift & Shift" approach in a custom network. Disable all traffic within the VPC and look at the Firewall logs to determine what traffic should be allowed for the application to work properly.
- B. Refactor the application into a micro-services architecture hosted in Cloud Functions in an isolated project.
Disable all traffic from outside your project using Firewall Rules. Use VPC Flow logs to determine what traffic should be allowed for the application to work properly. - C. Refactor the application into a micro-services architecture in a GKE cluster. Disable all traffic from outside the cluster using Firewall Rules. Use VPC Flow logs to determine what traffic should be allowed for the application to work properly.
- D. Migrate the application into an isolated project using a "Lift & Shift" approach. Enable all internal TCP traffic using VPC Firewall rules. Use VPC Flow logs to determine what traffic should be allowed for the application to work properly.
Answer: C
Explanation:
Explanation/Reference:
NEW QUESTION # 84
Applications often require access to "secrets" - small pieces of sensitive data at build or run time. The administrator managing these secrets on GCP wants to keep a track of "who did what, where, and when?" within their GCP projects.
Which two log streams would provide the information that the administrator is looking for? (Choose two.)
- A. Admin Activity logs
- B. VPC Flow logs
- C. Agent logs
- D. System Event logs
- E. Data Access logs
Answer: A,E
Explanation:
Explanation
https://cloud.google.com/secret-manager/docs/audit-logging
NEW QUESTION # 85
An application log's data, including customer identifiers such as email addresses, needs to be redacted. However, these logs also include the email addresses of internal developers from company.com, and these should NOT be redacted. Which solution should you use to meet these requirements?
- A. Create a regular custom dictionary detector to match all email addresses listed in Cloud Identity.
- B. Create a regular custom dictionary detector that lists a subset of the developers' email addresses.
- C. Create a regular expression (regex) custom infoType detector to match on @company.com.
- D. Create a custom infoType called COMPANY_EMAIL to match @company.com.
Answer: C
Explanation:
A is not correct because as all company.com email addresses are sensitive and should be filtered, a static list is hard to maintain and can easily miss sensitive data.
B is correct because the regex will detect all company.com email addresses that need to be protected and written to the log file.
C is not correct because as the user base in Cloud Identity might only be a subset of all emails that need to be protected.
D is not correct because you need to specify a detector within the custom infoType and the detector should be a regular expression to match all @company.com email addresses.
https://cloud.google.com/dlp/docs/infotypes-reference
https://cloud.google.com/dlp/docs/creating-custom-infotypes
NEW QUESTION # 86
An organization is migrating from their current on-premises productivity software systems to G Suite. Some network security controls were in place that were mandated by a regulatory body in their region for their previous on-premises system. The organization's risk team wants to ensure that network security controls are maintained and effective in G Suite. A security architect supporting this migration has been asked to ensure that network security controls are in place as part of the new shared responsibility model between the organization and Google Cloud.
What solution would help meet the requirements?
- A. Network security is a built-in solution and Google's Cloud responsibility for SaaS products like G Suite.
- B. Ensure that firewall rules are in place to meet the required controls.
- C. Set up Cloud Armor to ensure that network security controls can be managed for G Suite.
- D. Set up an array of Virtual Private Cloud (VPC) networks to control network security as mandated by the relevant regulation.
Answer: A
Explanation:
Explanation
https://gsuite.google.com/learn-more/security/security-whitepaper/page-1.html Shared responsibility "Security of the Cloud" - GCP is responsible for protecting the infrastructure that runs all of the services offered in the GCP Cloud. This infrastructure is composed of the hardware, software, networking, and facilities that run GCP Cloud services.
NEW QUESTION # 87
You need to set up a Cloud interconnect connection between your company's on-premises data center and VPC host network. You want to make sure that on-premises applications can only access Google APIs over the Cloud Interconnect and not through the public internet. You are required to only use APIs that are supported by VPC Service Controls to mitigate against exfiltration risk to non-supported APIs. How should you configure the network?
- A. Use restricted googleapis.com to access Google APIs using a set of IP addresses only routable from within Google Cloud, which are advertised as routes over the Cloud Interconnect connection.
- B. Enable Private Google Access on the regional subnets and global dynamic routing mode.
- C. Set up a Private Service Connect endpoint IP address with the API bundle of "all-apis", which is advertised as a route over the Cloud interconnect connection.
- D. Use private.googleapis.com to access Google APIs using a set of IP addresses only routable from within Google Cloud, which are advertised as routes over the connection.
Answer: A
Explanation:
Explanation
https://cloud.google.com/vpc/docs/private-service-connect
An API bundle:
All APIs (all-apis): most Google APIs
(same as private.googleapis.com).
VPC-SC (vpc-sc): APIs that VPC Service Controls supports
(same as restricted.googleapis.com).
VMs in the same VPC network as the endpoint (all regions)
On-premises systems that are connected to the VPC network that contains the endpoint
NEW QUESTION # 88
A large financial institution is moving its Big Data analytics to Google Cloud Platform. They want to have maximum control over the encryption process of data stored at rest in BigQuery.
What technique should the institution use?
- A. Use a Cloud Hardware Security Module (Cloud HSM).
- B. Customer-managed encryption keys (CMEK).
- C. Customer-supplied encryption keys (CSEK).
- D. Use Cloud Storage as a federated Data Source.
Answer: B
Explanation:
Explanation
If you want to manage the key encryption keys used for your data at rest, instead of having Google manage the keys, use Cloud Key Management Service to manage your keys. This scenario is known as customer-managed encryption keys (CMEK). https://cloud.google.com/bigquery/docs/encryption-at-rest
NEW QUESTION # 89
Applications often require access to "secrets" - small pieces of sensitive data at build or run time. The administrator managing these secrets on GCP wants to keep a track of "who did what, where, and when?" within their GCP projects.
Which two log streams would provide the information that the administrator is looking for? (Choose two.)
- A. Admin Activity logs
- B. VPC Flow logs
- C. Agent logs
- D. System Event logs
- E. Data Access logs
Answer: A,E
NEW QUESTION # 90
You need to follow Google-recommended practices to leverage envelope encryption and encrypt data at the application layer.
What should you do?
- A. Generate a data encryption key (DEK) locally to encrypt the data, and generate a new key encryption key (KEK) in Cloud KMS to encrypt the DEK. Store both the encrypted data and the encrypted DEK.
- B. Generate a data encryption key (DEK) locally to encrypt the data, and generate a new key encryption key (KEK) in Cloud KMS to encrypt the DEK. Store both the encrypted data and the KEK.
- C. Generate a new data encryption key (DEK) in Cloud KMS to encrypt the data, and generate a key encryption key (KEK) locally to encrypt the key. Store both the encrypted data and the KEK.
- D. Generate a new data encryption key (DEK) in Cloud KMS to encrypt the data, and generate a key encryption key (KEK) locally to encrypt the key. Store both the encrypted data and the encrypted DEK.
Answer: A
Explanation:
https://cloud.google.com/kms/docs/envelope-encryption
NEW QUESTION # 91
You are part of a security team that wants to ensure that a Cloud Storage bucket in Project A can only be readable from Project B.
You also want to ensure that data in the Cloud Storage bucket cannot be accessed from or copied to Cloud Storage buckets outside the network, even if the user has the correct credentials.
What should you do?
- A. Enable VPC Service Controls, create a perimeter with Project A and B, and include Cloud Storage service.
- B. Enable Private Access in Project A and B networks with strict firewall rules to allow communication between the networks.
- C. Enable VPC Peering between Project A and B networks with strict firewall rules to allow communication between the networks.
- D. Enable Domain Restricted Sharing Organization Policy and Bucket Policy Only on the Cloud Storage bucket.
Answer: D
Explanation:
https://cloud.google.com/resource-manager/docs/organization-policy/restricting-domains
NEW QUESTION # 92
Your company is using Cloud Dataproc for its Spark and Hadoop jobs. You want to be able to create, rotate, and destroy symmetric encryption keys used for the persistent disks used by Cloud Dataproc. Keys can be stored in the cloud.
What should you do?
- A. Use customer-supplied encryption keys to manage the data encryption key (DEK).
- B. Use customer-supplied encryption keys to manage the key encryption key (KEK).
- C. Use the Cloud Key Management Service to manage the key encryption key (KEK).
- D. Use the Cloud Key Management Service to manage the data encryption key (DEK).
Answer: D
NEW QUESTION # 93
You are in charge of creating a new Google Cloud organization for your company. Which two actions should you take when creating the super administrator accounts? (Choose two.)
- A. Use a private connection to create the super admin accounts to avoid sending your credentials over the Internet.
- B. Use a physical token to secure the super admin credentials with multi-factor authentication (MFA).
- C. Provide non-privileged identities to the super admin users for their day-to-day activities.
- D. Disable any Identity and Access Management (1AM) roles for super admin at the organization level in the Google Cloud Console.
- E. Create an access level in the Google Admin console to prevent super admin from logging in to Google Cloud.
Answer: B,C
Explanation:
Explanation
https://cloud.google.com/resource-manager/docs/super-admin-best-practices#discourage_super_admin_account_
- Use a security key or other physical authentication device to enforce two-step verification - Give super admins a separate account that requires a separate login
NEW QUESTION # 94
You are working with a client that is concerned about control of their encryption keys for sensitive data. The client does not want to store encryption keys at rest in the same cloud service provider (CSP) as the data that the keys are encrypting. Which Google Cloud encryption solutions should you recommend to this client?
(Choose two.)
- A. Cloud External Key Manager
- B. Secret Manager
- C. Customer-supplied encryption keys.
- D. Customer-managed encryption keys
- E. Google default encryption
Answer: A,C
NEW QUESTION # 95
Your team wants to centrally manage GCP IAM permissions from their on-premises Active Directory Service. Your team wants to manage permissions by AD group membership.
What should your team do to meet these requirements?
- A. Use the Admin SDK to create groups and assign IAM permissions from Active Directory.
- B. Use the Cloud Identity and Access Management API to create groups and IAM permissions from Active Directory.
- C. Set up Cloud Directory Sync to sync groups, and set IAM permissions on the groups.
- D. Set up SAML 2.0 Single Sign-On (SSO), and assign IAM permissions to the groups.
Answer: D
NEW QUESTION # 96
While migrating your organization's infrastructure to GCP, a large number of users will need to access GCP Console. The Identity Management team already has a well-established way to manage your users and want to keep using your existing Active Directory or LDAP server along with the existing SSO password.
What should you do?
- A. Users sign in directly to the GCP Console using the credentials from your on-premises Kerberos compliant identity provider.
- B. Users sign in using OpenID (OIDC) compatible IdP, receive an authentication token, then use that token to log in to the GCP Console.
- C. Manually synchronize the data in Google domain with your existing Active Directory or LDAP server.
- D. Use Google Cloud Directory Sync to synchronize the data in Google domain with your existing Active Directory or LDAP server.
Answer: D
Explanation:
https://cloud.google.com/blog/products/identity-security/using-your-existing-identity-management- system-with-google-cloud-platform
NEW QUESTION # 97
Your Security team believes that a former employee of your company gained unauthorized access to Google Cloud resources some time in the past 2 months by using a service account key. You need to confirm the unauthorized access and determine the user activity. What should you do?
- A. Use the Logs Explorer to search for user activity.
- B. Use Security Health Analytics to determine user activity.
- C. Use the Cloud Monitoring console to filter audit logs by user.
- D. Use the Cloud Data Loss Prevention API to query logs in Cloud Storage.
Answer: C
NEW QUESTION # 98
A website design company recently migrated all customer sites to App Engine. Some sites are still in progress and should only be visible to customers and company employees from any location.
Which solution will restrict access to the in-progress sites?
- A. Create an App Engine firewall rule that allows access from the customer and employee networks and denies all other traffic.
- B. Use Cloud VPN to create a VPN connection between the relevant on-premises networks and the company's GCP Virtual Private Cloud (VPC) network.
- C. Upload an .htaccess file containing the customer and employee user accounts to App Engine.
- D. Enable Cloud Identity-Aware Proxy (IAP), and allow access to a Google Group that contains the customer and employee user accounts.
Answer: D
NEW QUESTION # 99
You perform a security assessment on a customer architecture and discover that multiple VMs have public IP addresses. After providing a recommendation to remove the public IP addresses, you are told those VMs need to communicate to external sites as part of the customer's typical operations. What should you recommend to reduce the need for public IP addresses in your customer's VMs?
- A. Cloud VPN
- B. Cloud NAT
- C. Cloud Router
- D. Google Cloud Armor
Answer: A
NEW QUESTION # 100
While migrating your organization's infrastructure to GCP, a large number of users will need to access GCP Console. The Identity Management team already has a well-established way to manage your users and want to keep using your existing Active Directory or LDAP server along with the existing SSO password.
What should you do?
- A. Users sign in directly to the GCP Console using the credentials from your on-premises Kerberos compliant identity provider.
- B. Users sign in using OpenID (OIDC) compatible IdP, receive an authentication token, then use that token to log in to the GCP Console.
- C. Manually synchronize the data in Google domain with your existing Active Directory or LDAP server.
- D. Use Google Cloud Directory Sync to synchronize the data in Google domain with your existing Active Directory or LDAP server.
Answer: D
Explanation:
Reference:
https://cloud.google.com/blog/products/identity-security/using-your-existing-identity-management- system-with-google-cloud-platform
NEW QUESTION # 101
......
For more information visit:
Google Professional Cloud Security Engineer Exam Reference
Achieving the Google Professional-Cloud-Security-Engineer certification demonstrates that an IT professional has the skills and knowledge to secure Google Cloud infrastructure and services effectively. It serves as a validation of their expertise in cloud security and can enhance career opportunities, increase earning potential, and demonstrate a commitment to professional development. Overall, the Google Professional-Cloud-Security-Engineer certification is an excellent way for IT professionals to demonstrate their expertise in cloud security and gain a competitive edge in the job market.
Easy Success Google Professional-Cloud-Security-Engineer Exam in First Try: https://passleader.torrentvalid.com/Professional-Cloud-Security-Engineer-valid-braindumps-torrent.html