Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 245 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 245

Select 3Google Cloud Platform

You are configuring a Shared VPC in Google Cloud to centralize network management for multiple projects. The host project contains a VPC network with several subnets, and you need to ensure that the service project can only deploy resources in specific subnets while maintaining appropriate security. Which of the following steps should you perform to meet this requirement?

  1. A

    Grant the 'Compute Network User' role for the specific subnets to the service project’s service account.

  2. B

    Grant the 'Compute Security Admin' role for the host project to the service project’s service account.

  3. C

    Configure firewall rules in the host project to restrict traffic to and from the specific subnets.

  4. D

    Enable VPC peering between the host project and the service project.

  5. E

    Verify that the service project’s service account is added as a Shared VPC service project.

Show answer and explanation

Correct answers: A, C, E

Explanation

In a Shared VPC setup, the service project must first be added as a service project to the host project. The 'Compute Network User' role must then be assigned at the subnet level to restrict resource deployment to specific subnets. Firewall rules in the host project ensure that network traffic to and from the subnets is properly secured. These steps collectively enforce security and controlled access while enabling centralized network management.

  • A. Correct.

    Granting the 'Compute Network User' role at the subnet level allows the service project to deploy resources only in the specified subnets. This is required to enforce subnet-specific access permissions.

  • B. Incorrect.

    The 'Compute Security Admin' role grants broad security-related permissions over the entire project, which is unnecessary and overly permissive for this scenario.

  • C. Correct.

    Firewall rules in the host project are necessary to control the traffic to and from the subnets, ensuring security for resources deployed in the service project.

  • D. Incorrect.

    VPC peering is not required in this scenario because Shared VPC directly connects the host and service projects without the need for peering.

  • E. Correct.

    Adding the service project as a Shared VPC service project is a prerequisite for allowing the service project to use the host project’s VPC network.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam