Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 229 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 229

Select 3Google Cloud Platform

Your organization uses multiple Google Cloud APIs to manage its cloud infrastructure. As a security engineer, you are tasked with ensuring that only the APIs necessary for day-to-day operations remain enabled, and any unused APIs are disabled to reduce the attack surface. Additionally, you need to monitor API usage over time to identify any anomalies. Which actions should you take to achieve this?

  1. A

    Use Cloud Asset Inventory to identify all enabled APIs in your project and disable unused APIs.

  2. B

    Enable Cloud Audit Logs for 'Admin Activity' and 'Data Access' logs to monitor API usage.

  3. C

    Use VPC Service Controls to restrict API calls to specific IP ranges.

  4. D

    Set up alerts in Cloud Monitoring for unusual API activity patterns.

  5. E

    Use Identity and Access Management (IAM) to block all APIs by default and allow them only when needed.

Show answer and explanation

Correct answers: A, B, D

Explanation

To continually monitor and restrict configured APIs, you need to identify currently enabled APIs, monitor their usage, and disable unused ones. Cloud Asset Inventory helps identify active APIs, while Cloud Audit Logs and Cloud Monitoring allow you to track API usage and detect anomalies. VPC Service Controls and IAM are useful for restricting access but are not specifically designed for monitoring or managing API usage.

  • A. Correct.

    Cloud Asset Inventory provides a comprehensive list of all resources in your project, including enabled APIs. By reviewing this list, you can identify and disable any APIs that are not in use, reducing the attack surface.

  • B. Correct.

    Cloud Audit Logs provide detailed records of API activity, allowing you to monitor usage and detect unauthorized or unusual access.

  • C. Incorrect.

    While VPC Service Controls can restrict access to APIs from specific IP ranges, this does not help directly with identifying or disabling unused APIs or monitoring for anomalies.

  • D. Correct.

    Cloud Monitoring can be configured to detect unusual API activity and send alerts, helping to identify potential security incidents.

  • E. Incorrect.

    IAM can restrict access to APIs by managing permissions, but blocking all APIs by default and allowing them only when needed may not be practical for most organizations and is not a recommended approach for monitoring or managing API usage.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam