Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 139 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 139

Select 2Google Cloud Platform

Your organization wants to restrict access to a sensitive internal application hosted on Google Cloud based on users' physical location and device security posture. You are tasked with configuring Access Context Manager to meet this requirement. Which steps should you perform to achieve this?

  1. A

    Create an access level with conditions based on IP subnets and device policy.

  2. B

    Assign the access level to the organization’s folder.

  3. C

    Create a VPC Service Control perimeter and include the access level in its configuration.

  4. D

    Create a policy tag and assign it to the application.

  5. E

    Use the Google Cloud Console to associate the access level with the targeted resource.

Show answer and explanation

Correct answers: A, C

Explanation

Access Context Manager allows you to define and enforce access restrictions based on attributes like user location or device security posture. To implement this, you first create an access level with the necessary conditions, such as IP subnet or device compliance. This access level is then used in conjunction with a VPC Service Control perimeter to enforce the restrictions on targeted resources. Other options, such as assigning access levels to folders or using policy tags, do not align with the functionality of Access Context Manager.

  • A. Correct.

    Correct: Creating an access level with conditions such as IP subnets or device policies is a key step in defining restrictions for Access Context Manager.

  • B. Incorrect.

    Incorrect: Access levels are not assigned directly to folders; instead, they are used in conjunction with service perimeters or IAM to control access.

  • C. Correct.

    Correct: A VPC Service Control perimeter must be used to enforce the access level, as it ensures the defined conditions are applied to the targeted resources.

  • D. Incorrect.

    Incorrect: Policy tags are not related to Access Context Manager; they are used for resource tagging and organization but do not enforce access restrictions.

  • E. Incorrect.

    Incorrect: Access levels are not directly associated with resources in the Google Cloud Console. They are typically used within service perimeters or IAM policies to apply restrictions.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam