Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 238 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 238

Select 2Google Cloud Platform

You are designing the network architecture for a company that hosts multiple applications in Google Cloud. These applications belong to separate business units and must not communicate with each other, except for specific APIs exposed through secure channels. Which Google Cloud configurations should you implement to achieve boundary segmentation between these applications while ensuring scalability and security?

  1. A

    Use separate Virtual Private Cloud (VPC) networks for each business unit and configure VPC peering only for the APIs that need to communicate.

  2. B

    Implement Shared VPC and use firewall rules to isolate traffic between different business units.

  3. C

    Use hierarchical firewall policies to enforce organization-wide segmentation by restricting traffic between projects belonging to different business units.

  4. D

    Use a single VPC network for all applications, but separate them using subnet-level routing and firewall rules.

  5. E

    Deploy Google Cloud Armor to block unwanted traffic between the business units.

Show answer and explanation

Correct answers: A, C

Explanation

Boundary segmentation in Google Cloud is essential when applications from separate business units need to be isolated for security and compliance reasons. Using separate VPCs per business unit ensures strong network isolation, while hierarchical firewall policies enforce consistent segmentation rules at the organization level. These approaches provide both scalability and security, which are critical for enterprise-grade architectures.

  • A. Correct.

    Correct: Using separate VPCs for each business unit ensures strong isolation between the networks. VPC peering can be configured for specific APIs that require communication, maintaining both boundary segmentation and necessary connectivity.

  • B. Incorrect.

    Incorrect: While Shared VPC allows central management of network resources, it doesn't inherently isolate traffic between business units. Firewall rules alone may not provide sufficient segmentation or scalability for this use case.

  • C. Correct.

    Correct: Hierarchical firewall policies are ideal for enforcing consistent organization-wide segmentation rules across all projects. They allow you to restrict traffic effectively and are scalable for large organizations with multiple business units.

  • D. Incorrect.

    Incorrect: A single VPC with subnet-level routing and firewall rules might provide basic segmentation, but it lacks the strong isolation needed between business units. It also becomes complex and less secure as the number of applications grows.

  • E. Incorrect.

    Incorrect: Google Cloud Armor is primarily used for protecting applications from external threats (e.g., DDoS attacks) and does not address internal network segmentation between business units.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam