Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 224 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 224

Select 2Google Cloud Platform

Your organization uses Cloud DNS to manage DNS records for its domain. The security team has requested that you configure Cloud DNS to prevent unauthorized access and protect against DNS spoofing attacks. Which two actions should you take to meet these requirements?

  1. A

    Enable DNSSEC for your Cloud DNS zones.

  2. B

    Configure fine-grained IAM roles for your Cloud DNS resources.

  3. C

    Disable logging for DNS queries to enhance performance.

  4. D

    Use Cloud Armor to restrict access to your DNS records.

  5. E

    Use private DNS zones for internal services.

Show answer and explanation

Correct answers: A, B

Explanation

To enhance the security of your Cloud DNS configuration, enabling DNSSEC ensures the integrity and authenticity of DNS responses, which protects against DNS spoofing. Additionally, setting up fine-grained IAM roles helps enforce strict access controls, preventing unauthorized users from modifying or accessing DNS configurations. These two measures are key to securing Cloud DNS effectively.

  • A. Correct.

    Enabling DNSSEC (Domain Name System Security Extensions) helps prevent DNS spoofing by ensuring DNS responses are authentic and have not been tampered with.

  • B. Correct.

    Configuring fine-grained IAM roles allows you to control who can access and manage your Cloud DNS resources, reducing the likelihood of unauthorized access.

  • C. Incorrect.

    Disabling logging does not enhance security; instead, it may hinder your ability to monitor and audit DNS activity for potential threats.

  • D. Incorrect.

    Cloud Armor is primarily used for protecting web applications against DDoS and other attacks, not for managing DNS security.

  • E. Incorrect.

    Using private DNS zones is useful for isolating internal services, but it does not address the broader concerns of unauthorized access or DNS spoofing for public zones.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam