Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 197 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 197

Select 2Google Cloud Platform

Your organization is hosting a web application on Google Cloud that must be accessible to authenticated users only. The application runs behind an HTTPS load balancer, and unauthorized access attempts must be blocked at the network perimeter. Which combination of configurations should you implement to meet these requirements?

  1. A

    Configure Identity-Aware Proxy (IAP) on the HTTPS load balancer and enforce user authentication.

  2. B

    Set up Cloud Next Generation Firewall (Cloud NGFW) rules to allow traffic only from trusted IP ranges.

  3. C

    Use Certificate Authority Service to issue a private certificate for the load balancer's backend.

  4. D

    Enable Google-managed SSL certificates on the HTTPS load balancer to secure the front-end connection.

  5. E

    Create a Cloud Armor security policy to block requests from known malicious IP addresses.

Show answer and explanation

Correct answers: A, D

Explanation

To secure the web application and ensure only authenticated users can access it, you need to configure Identity-Aware Proxy (IAP) on the HTTPS load balancer, as it enforces user authentication and authorization. Additionally, enabling Google-managed SSL certificates ensures secure communication between the client and the load balancer, protecting data in transit. While other options like NGFW rules and Cloud Armor policies can complement security, they do not directly address the requirement to enforce user authentication.

  • A. Correct.

    Correct. Configuring Identity-Aware Proxy (IAP) ensures that only authenticated users can access the application. IAP integrates with Google accounts to enforce user authentication and authorization.

  • B. Incorrect.

    Incorrect. While NGFW rules can restrict traffic based on trusted IP ranges, they are not sufficient for enforcing user authentication. This option does not meet the requirement of allowing access only to authenticated users.

  • C. Incorrect.

    Incorrect. While Certificate Authority Service can issue private certificates for backend communication, it is not directly related to user authentication or securing the application for external access.

  • D. Correct.

    Correct. Enabling Google-managed SSL certificates ensures secure HTTPS communication between clients and the load balancer, meeting the requirement to protect data in transit.

  • E. Incorrect.

    Incorrect. Cloud Armor security policies are useful for blocking malicious traffic, but they do not enforce user authentication and are not sufficient to meet the requirement.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam