Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 223 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 223

Select 3Google Cloud Platform

Your organization uses Cloud DNS to manage its domain records. As part of a new security policy, you are required to prevent unauthorized external entities from accessing your Cloud DNS zones while ensuring that authorized services within your organization can still resolve DNS queries. Which of the following security configurations should you apply?

  1. A

    Configure DNS policies to block external IP addresses from resolving DNS queries.

  2. B

    Use VPC Service Controls to restrict Cloud DNS API access to specific VPCs.

  3. C

    Enable DNSSEC for your Cloud DNS zones to ensure data integrity and authenticity.

  4. D

    Use private DNS zones for internal services and configure appropriate VPC attachments.

  5. E

    Set IAM permissions to allow only specific service accounts to create or modify DNS records.

Show answer and explanation

Correct answers: B, D, E

Explanation

To secure Cloud DNS zones, you should combine multiple security measures: using VPC Service Controls to restrict API access, configuring private DNS zones for internal services, and applying IAM permissions to control who can manage DNS records. These measures collectively ensure both API-level and query-level security while meeting the organization's requirements.

  • A. Incorrect.

    While DNS policies can be used to filter and route DNS queries, blocking external IPs is not a Cloud DNS feature. Instead, you should use other network configuration methods like VPC firewall rules.

  • B. Correct.

    Using VPC Service Controls can restrict access to the Cloud DNS API from external networks and unauthorized VPCs, ensuring that only specific VPCs can manage DNS resources.

  • C. Incorrect.

    DNSSEC provides integrity and authenticity for DNS data but does not directly control access to Cloud DNS zones or restrict unauthorized entities.

  • D. Correct.

    Private DNS zones are designed for internal services, ensuring that DNS queries are only resolvable within the attached VPCs. This prevents external access and aligns with the security requirement.

  • E. Correct.

    Restricting IAM permissions ensures that only authorized service accounts or users can create or modify DNS records, reducing the risk of unauthorized changes or access.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam