Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 250 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 250

Select 2Google Cloud Platform

You are designing a three-tier web application (frontend, application, and database tiers) on Google Cloud. The application requires strict network isolation between each tier while allowing the frontend tier to communicate with the application tier, and the application tier to communicate with the database tier. Which of the following steps should you take to configure network isolation and data encapsulation for the application?

  1. A

    Create separate VPC networks for each tier and use VPC Network Peering to allow inter-tier communication.

  2. B

    Use subnetworks for each tier within a single VPC and configure firewall rules to allow only required inter-tier traffic.

  3. C

    Deploy each tier in separate service accounts and configure IAM roles to restrict access between the tiers.

  4. D

    Use Private Service Connect to establish secure communication between the application and database tiers.

  5. E

    Enable VPC Service Controls for the project to isolate and secure the tiers.

Show answer and explanation

Correct answers: B, D

Explanation

To achieve network isolation and data encapsulation in an N-tier application, it is best to use subnetworks within a single VPC for logical separation and configure firewall rules for precise inter-tier communication. For secure communication between the application and database tiers, Private Service Connect is an effective solution as it ensures private and secure connectivity without exposing services.

  • A. Incorrect.

    Incorrect. Creating separate VPC networks for each tier would lead to overly complicated network management. VPC Network Peering does not provide granular control over inter-tier communication.

  • B. Correct.

    Correct. Using subnetworks for each tier within a single VPC provides logical network isolation while allowing you to configure precise, tier-specific firewall rules for inter-tier traffic.

  • C. Incorrect.

    Incorrect. Service accounts and IAM roles are more focused on identity and access management rather than network isolation and data encapsulation.

  • D. Correct.

    Correct. Private Service Connect is a secure way to enable communication between services, such as the application and database tiers, without exposing them publicly.

  • E. Incorrect.

    Incorrect. While VPC Service Controls enhance data security, they are primarily used to secure access to Google-managed services rather than isolating tiers in an N-tier application.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam