Google Professional Cloud Database Engineer exam dumps

Google Professional Cloud Database Engineer practice question 54 of 259

Professional Cloud Database Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Database Engineer Question 54

Select 4Google Cloud Platform

You are configuring a Cloud SQL instance for a MySQL database. Your security requirements include encrypting data using a customer-managed encryption key (CMEK) and ensuring secure client access using SSL certificates. Additionally, you want to restrict database access to specific applications deployed on Google Cloud. Which of the following steps should you take to meet these requirements?

  1. A

    Enable CMEK during the creation of the Cloud SQL instance and provide the appropriate Cloud Key Management Service (Cloud KMS) key.

  2. B

    Generate a private SSL certificate in Cloud SQL and distribute it to all client applications that will connect to the database.

  3. C

    Deploy the Cloud SQL Auth Proxy on the client application servers to securely connect to the Cloud SQL instance.

  4. D

    Enable public IP access for the Cloud SQL instance and restrict access using a firewall rule.

  5. E

    Configure the IAM policy for the Cloud SQL instance to grant the 'Cloud SQL Client' role to the service accounts used by the client applications.

Show answer and explanation

Correct answers: A, B, C, E

Explanation

To secure a Cloud SQL instance, you must meet encryption, secure communication, and access restriction requirements. Enabling CMEK ensures that data is encrypted using a customer-managed key. Using SSL certificates and deploying the Cloud SQL Auth Proxy ensures secure communication between clients and the database. Restricting access to specific applications is achieved by assigning the 'Cloud SQL Client' role to their service accounts. Public IP access should generally be avoided to reduce exposure to potential threats.

  • A. Correct.

    Correct: Enabling CMEK during the creation of the Cloud SQL instance ensures that data is encrypted using a key you control in Cloud KMS, meeting the encryption requirement.

  • B. Correct.

    Correct: Generating and using SSL certificates ensures secure client-server communication, meeting the requirement for secure client access.

  • C. Correct.

    Correct: The Cloud SQL Auth Proxy establishes a secure connection between client applications and the database while managing authentication and encryption.

  • D. Incorrect.

    Incorrect: Enabling public IP access increases exposure to potential threats. Instead, private IP access and secure proxies are recommended for better security.

  • E. Correct.

    Correct: Granting the 'Cloud SQL Client' role to service accounts ensures that only authorized applications can connect to the Cloud SQL instance, which fulfills the access restriction requirement.

Timed practice exam

Take a Google Professional Cloud Database Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam