Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 227 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 227

Select 3Google Cloud Platform

Your company uses Google Cloud DNS to manage internal and external domains. To enhance security, you need to configure DNS settings to prevent unauthorized access to sensitive zones and ensure DNS queries are encrypted. Which settings should you configure?

  1. A

    Enable DNSSEC for zones to protect against DNS spoofing.

  2. B

    Use Private DNS zones for internal services and limit access using IAM policies.

  3. C

    Enable DNS over HTTPS (DoH) for encrypted DNS queries.

  4. D

    Use Cloud Armor to restrict access to Cloud DNS zones.

  5. E

    Configure logging for DNS queries to monitor potential security issues.

Show answer and explanation

Correct answers: A, B, C

Explanation

Securing Cloud DNS involves enabling DNSSEC to protect against spoofing, using Private DNS zones with IAM policies to restrict access, and encrypting DNS queries with DNS over HTTPS (DoH). These configurations directly enhance DNS security. Logging and using Cloud Armor are valuable but do not directly address the specific security requirements for DNS.

  • A. Correct.

    Enabling DNSSEC ensures that DNS records are signed and validated, preventing DNS spoofing and ensuring data integrity.

  • B. Correct.

    Private DNS zones are useful for internal services, and using IAM policies ensures only authorized users or services can access the zones.

  • C. Correct.

    DNS over HTTPS (DoH) encrypts DNS queries, protecting them from interception or tampering.

  • D. Incorrect.

    Cloud Armor is a web application firewall and cannot directly restrict access to Cloud DNS zones.

  • E. Incorrect.

    While logging DNS queries can help monitor security issues, it does not directly enhance security for DNS settings.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam