Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 246 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 246

Select 2Google Cloud Platform

You are designing a multi-tier application hosted on Google Cloud. The application consists of a public-facing frontend, an internal application layer, and a database backend. You need to ensure proper network isolation and data encapsulation between the tiers while allowing only the necessary communication between them. Which of the following actions should you take to achieve this?

  1. A

    Create separate Virtual Private Cloud (VPC) networks for each tier and use VPC Network Peering to interconnect them.

  2. B

    Place each tier in a separate subnet within the same VPC and configure firewall rules to restrict communication to only necessary ports.

  3. C

    Use Private Google Access to ensure backend services can securely connect to Google APIs without public IP addresses.

  4. D

    Configure a Shared VPC and assign each tier to a different project, ensuring IAM roles restrict access to the network resources.

  5. E

    Enable VPC Service Controls to define service perimeters and restrict data movement between tiers.

Show answer and explanation

Correct answers: B, C

Explanation

To configure network isolation and data encapsulation for N-tier applications, you should place each tier in separate subnets within the same VPC and use firewall rules to restrict communication to the necessary ports. Additionally, Private Google Access ensures secure connectivity for backend services to Google APIs without exposing them to the public internet. These measures effectively achieve the required isolation and security for this scenario.

  • A. Incorrect.

    Creating separate VPCs for each tier and using VPC Network Peering is unnecessarily complex for this use case. VPC Network Peering is not granular enough to enforce tier-specific communication policies, making it suboptimal for network isolation in this scenario.

  • B. Correct.

    Placing each tier in a separate subnet and using firewall rules to restrict communication is an effective way to isolate the tiers while allowing only the required traffic. This approach aligns with the principle of least privilege for network access.

  • C. Correct.

    Using Private Google Access ensures that backend services (e.g., database tier) can securely connect to Google APIs without exposing them to the public internet. This enhances security and is a recommended practice for private communication.

  • D. Incorrect.

    While a Shared VPC can centralize network management across projects, it is not directly relevant to achieving network isolation and data encapsulation within the same application tiers. IAM roles focus on access control rather than traffic isolation between tiers.

  • E. Incorrect.

    VPC Service Controls are designed to protect data movement between Google Cloud services rather than isolating network traffic between application tiers. They are not suited for tier-specific network isolation.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam