Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 221 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 221

Select 2Google Cloud Platform

Your organization requires all outbound web traffic from its virtual machines in Google Cloud to be inspected and logged for security compliance. You have been tasked with deploying a secure web proxy solution. Which steps should you take to implement this securely and effectively?

  1. A

    Deploy a managed proxy solution using Google Cloud Armor to filter outbound web traffic.

  2. B

    Configure Cloud NAT to route outbound traffic from virtual machines through a third-party secure web proxy.

  3. C

    Use the Squid proxy in a Compute Engine instance and configure the virtual machine firewall rules to restrict traffic only to the proxy.

  4. D

    Enable VPC Service Controls to ensure that all outbound web traffic is routed through the Google-managed proxy.

  5. E

    Set up a private Google Kubernetes Engine (GKE) cluster and deploy a secure web proxy containerized application.

Show answer and explanation

Correct answers: B, C

Explanation

To deploy a secure web proxy for inspecting and logging outbound web traffic, you can either configure Cloud NAT to route traffic through a third-party proxy or use a proxy like Squid on a Compute Engine instance with appropriate firewall rules. These approaches ensure security, logging, and control over outbound traffic. Other options, such as using Google Cloud Armor or VPC Service Controls, do not directly address the need for a secure web proxy.

  • A. Incorrect.

    Google Cloud Armor is primarily used for protecting applications from web-based attacks like DDoS and does not act as a proxy for outbound traffic. This option is incorrect.

  • B. Correct.

    Configuring Cloud NAT to route outbound traffic through a third-party secure web proxy is a valid solution to inspect and log outbound traffic, as Cloud NAT enables Internet access for VMs without exposing them directly to the public Internet.

  • C. Correct.

    Using a Squid proxy on a Compute Engine instance with appropriate firewall rules ensures that all outbound traffic is routed and inspected through the proxy, making it a secure and effective solution.

  • D. Incorrect.

    VPC Service Controls are used to restrict data exfiltration from Google Cloud services and do not provide a way to route outbound web traffic through a proxy. This option is incorrect.

  • E. Incorrect.

    While deploying a containerized secure web proxy on GKE might be possible, it is unnecessarily complex for this use case and not a standard approach for deploying a secure web proxy for outbound VM traffic.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam