Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 194 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 194

Select 4Google Cloud Platform

Your organization has deployed a web application on Google Cloud that must serve users over HTTPS. The application is fronted by an HTTPS load balancer. To ensure secure access to the application, you need to enforce strict network perimeter controls, including protecting against unauthorized access, using managed certificates, and logging access requests. Which configuration steps should you take to meet these requirements?

  1. A

    Configure the HTTPS load balancer with an Identity-Aware Proxy (IAP) to restrict access to authenticated users.

  2. B

    Use the Certificate Authority Service to issue and manage SSL/TLS certificates for the HTTPS load balancer.

  3. C

    Set up Cloud Next Generation Firewall (Cloud NGFW) rules to allow traffic only from trusted IP ranges.

  4. D

    Enable audit logging for the HTTPS load balancer to track all access attempts.

  5. E

    Configure a TCP load balancer instead of an HTTPS load balancer for better performance.

Show answer and explanation

Correct answers: A, B, C, D

Explanation

To enforce network perimeter controls and ensure secure access to your web application, you need to implement Identity-Aware Proxy (IAP) for authentication, use the Certificate Authority Service to manage SSL/TLS certificates, create Cloud NGFW rules to restrict traffic to trusted sources, and enable audit logging for visibility into access attempts. These configurations collectively protect the application and meet security requirements. A TCP load balancer is not suitable for this scenario as it does not support HTTPS.

  • A. Correct.

    Configuring Identity-Aware Proxy (IAP) ensures that only authenticated users can access the application, adding an additional layer of security.

  • B. Correct.

    Using the Certificate Authority Service ensures SSL/TLS certificates are managed securely and automatically renewed, meeting the requirement for secure HTTPS connections.

  • C. Correct.

    Setting up Cloud NGFW rules to allow traffic only from trusted IP ranges enforces network perimeter security by controlling which sources can access the application.

  • D. Correct.

    Enabling audit logging for the HTTPS load balancer provides visibility into access attempts, which is critical for monitoring and compliance.

  • E. Incorrect.

    A TCP load balancer does not provide HTTPS termination and encryption, which is required for secure connections to the web application.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam