Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 237 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 237

Select 2Google Cloud Platform

Your organization is designing a multi-tier application hosted on Google Cloud. To enhance security, you need to configure boundary segmentation between the web tier, application tier, and database tier. Which of the following actions should you take to implement this boundary segmentation effectively?

  1. A

    Create separate VPC networks for each tier and use VPC Peering to connect them.

  2. B

    Use subnetworks to isolate each tier within the same VPC network and configure firewall rules to control traffic between them.

  3. C

    Implement Private Google Access to ensure inter-tier communication remains private.

  4. D

    Leverage Identity and Access Management (IAM) roles to restrict access between the tiers.

  5. E

    Set up hierarchical firewall policies to enforce organization-wide segmentation rules.

Show answer and explanation

Correct answers: B, E

Explanation

Boundary segmentation in Google Cloud often involves the use of subnetworks within a single VPC to logically separate resources (e.g., web, application, and database tiers). Configuring firewall rules for these subnetworks ensures precise control over inter-tier communication. Additionally, hierarchical firewall policies can be used to enforce organization-wide segmentation standards, ensuring consistent security rules across projects and environments.

  • A. Incorrect.

    Creating separate VPC networks for each tier and using VPC Peering can add complexity without significantly enhancing security. Inter-tier communication through VPC Peering may still require additional firewall rules, and it is generally better to use subnetworks for segmentation within a single VPC.

  • B. Correct.

    Using subnetworks to isolate each tier within the same VPC network is a recommended approach for boundary segmentation. This allows for clear separation of resources and enables precise control of traffic using firewall rules.

  • C. Incorrect.

    Private Google Access is used to ensure resources within a private network can access Google APIs and services without using external IPs. It is not a method for inter-tier segmentation.

  • D. Incorrect.

    IAM roles are primarily used for managing permissions for Google Cloud resources and are not directly related to network segmentation between tiers.

  • E. Correct.

    Hierarchical firewall policies allow security rules to be applied at the organization or folder level, providing consistent enforcement of segmentation rules across multiple projects.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam