Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 142 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 142

Select 3Google Cloud Platform

You are a security engineer at an organization that uses Google Cloud. Your team wants to restrict access to a sensitive internal application hosted on Google Cloud to employees connecting from the corporate network or using company-managed devices. Which of the following steps are necessary to achieve this requirement using Access Context Manager?

  1. A

    Create an access level that includes conditions for IP subnets of the corporate network and device policies for company-managed devices.

  2. B

    Attach the access level to a service perimeter protecting the internal application.

  3. C

    Enable VPC Service Controls for your entire Google Cloud organization to enforce the access level.

  4. D

    Configure the access level to only allow requests from specific IAM roles.

  5. E

    Test the access level by simulating access requests from within and outside the corporate network.

Show answer and explanation

Correct answers: A, B, E

Explanation

To restrict access to a sensitive internal application using Access Context Manager, you must define an access level with the appropriate conditions (e.g., IP subnets and device policies) and attach it to a service perimeter protecting the application. Testing the access level is crucial to ensure it functions correctly. VPC Service Controls are not required for the entire organization, and access levels are attribute-based, not tied to specific IAM roles.

  • A. Correct.

    Correct: You need to create an access level with conditions that specify the corporate network's IP subnets and device policies for company-managed devices to enforce the required restrictions.

  • B. Correct.

    Correct: The access level needs to be attached to a service perimeter to protect the internal application and enforce the defined conditions.

  • C. Incorrect.

    Incorrect: VPC Service Controls are not required for the entire organization. Service perimeters are used selectively to protect specific resources.

  • D. Incorrect.

    Incorrect: Access levels do not control IAM roles but are used to define conditions for access based on attributes like IP, device type, or geographic location.

  • E. Correct.

    Correct: Testing access levels by simulating requests ensures that the conditions are enforced as expected and helps identify any misconfigurations.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam