Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 193 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 193

Select 2Google Cloud Platform

Your organization hosts a public-facing web application on Google Cloud that processes sensitive customer data. To enhance both security and access control, you need to ensure that external users can access the application only through a secure HTTPS connection, while internal administrative users are granted access based on their identity and device compliance. Which combination of network perimeter controls should you configure to meet these requirements?

  1. A

    Use Google Cloud Load Balancer with an SSL certificate from Certificate Authority Service to enforce HTTPS connections.

  2. B

    Configure Identity-Aware Proxy (IAP) to restrict access to internal administrative users based on their identity and device compliance.

  3. C

    Deploy Cloud Armor to block access from all unauthorized IP addresses.

  4. D

    Set up firewall rules in Cloud Next Generation Firewall (Cloud NGFW) to restrict access to the application to specific port ranges only.

  5. E

    Enable HTTPS redirect on the backend VMs hosting the application to enforce secure connections.

Show answer and explanation

Correct answers: A, B

Explanation

To meet the requirements, you need to enforce HTTPS for external users and identity-based access control for internal administrative users. A Google Cloud Load Balancer with an SSL certificate from Certificate Authority Service ensures secure HTTPS connections, while Identity-Aware Proxy (IAP) restricts access based on identity and device compliance. Other options, like Cloud Armor or firewall rules, do not directly address these specific requirements.

  • A. Correct.

    Correct: Using a Google Cloud Load Balancer with an SSL certificate from Certificate Authority Service ensures that all external connections are encrypted via HTTPS, meeting the requirement for secure connections.

  • B. Correct.

    Correct: Identity-Aware Proxy (IAP) allows you to enforce access control based on user identity and device compliance, which fulfills the need to restrict access for internal administrative users.

  • C. Incorrect.

    Incorrect: While Cloud Armor can block traffic based on IP ranges, this does not directly address the requirements for HTTPS enforcement or identity-based access control.

  • D. Incorrect.

    Incorrect: Restricting port ranges with Cloud NGFW does not fulfill the requirement to enforce HTTPS connections or implement identity-based access control.

  • E. Incorrect.

    Incorrect: Enabling HTTPS redirect on backend VMs does not provide the same level of security and scalability as using a load balancer with SSL termination.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam