Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 216 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 216

Single answerGoogle Cloud Platform

Your organization wants to deploy a secure web proxy on Google Cloud to ensure web traffic filtering, enforce internet usage policies, and inspect HTTPS traffic. Which approach should you take to deploy a secure web proxy while adhering to security best practices?

  1. A

    Use a third-party web proxy solution deployed on a Google Cloud VM in a secure private subnet.

  2. B

    Leverage Google Cloud Armor to configure web proxy capabilities for HTTPS inspection directly.

  3. C

    Use a managed web proxy solution from the Google Cloud Marketplace and configure it in a shared VPC for centralized management.

  4. D

    Deploy a Cloud Function to act as a custom web proxy and route all internet-bound traffic through it.

Show answer and explanation

Correct answer: A

Explanation

Deploying a secure web proxy involves using a robust solution that can handle traffic filtering, enforce policies, and inspect HTTPS traffic. A third-party web proxy deployed on a Google Cloud VM in a secure private subnet provides the required functionality and ensures security by isolating the proxy from public networks. Other options either lack the required capabilities or do not align with security best practices.

  • A. Correct.

    This is the correct answer. Deploying a third-party web proxy on a Google Cloud VM ensures that you have full control over traffic filtering and policy enforcement. Placing the proxy in a secure private subnet ensures isolation from public networks, aligning with security best practices.

  • B. Incorrect.

    Google Cloud Armor is a web application firewall (WAF) for protecting applications from common threats. It does not provide web proxy functionality or HTTPS inspection capabilities.

  • C. Incorrect.

    While managed solutions from the Google Cloud Marketplace can simplify deployment, configuring it in a shared VPC is not always the best approach for secure web proxy deployment. A shared VPC could expose the proxy to unnecessary risks if not properly isolated.

  • D. Incorrect.

    Cloud Functions are not designed to handle high-bandwidth traffic or act as a web proxy. This approach would be inefficient and insecure for web traffic filtering and HTTPS inspection.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam