Google Associate Cloud Engineer exam dumps

Google Associate Cloud Engineer practice question 234 of 375

Associate Cloud Engineer. Free level, Google Cloud. Free question with the correct answer and a full explanation.

Google Associate Cloud Engineer Question 234

Select 2Google Cloud Platform

You are managing a Google Cloud Storage bucket that contains sensitive financial data. To ensure data security, you want to enforce uniform bucket-level access to restrict public access and use a specific encryption key for all objects. What steps should you take to achieve this?

  1. A

    A. Enable Uniform bucket-level access on the bucket.

  2. B

    B. Use the default Google-managed encryption key for all objects.

  3. C

    C. Configure a custom IAM policy to restrict public access.

  4. D

    D. Use a Customer-Managed Encryption Key (CMEK) for the bucket.

  5. E

    E. Enable Object Versioning to maintain data history.

Show answer and explanation

Correct answers: A, D

Explanation

To achieve the goal of securing sensitive data in a Cloud Storage bucket, enabling Uniform bucket-level access ensures that all objects adhere to the same access policies, thus preventing public access. Additionally, using a Customer-Managed Encryption Key (CMEK) provides control over the encryption process, enhancing the security of the data stored in the bucket.

  • A. Correct.

    Enabling Uniform bucket-level access will apply the same access policies to all objects, preventing public access.

  • B. Incorrect.

    The default Google-managed encryption key is used by default and does not provide the additional control of a Customer-Managed Encryption Key (CMEK).

  • C. Incorrect.

    While custom IAM policies can restrict access, Uniform bucket-level access is a more comprehensive and simpler solution for this scenario.

  • D. Correct.

    Using a Customer-Managed Encryption Key (CMEK) allows you to control the encryption keys used for your data, adding an extra layer of security.

  • E. Incorrect.

    Object Versioning helps in maintaining data history but does not directly enhance the security of the data.

Timed practice exam

Take a Google Associate Cloud Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam