Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 288 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 288

Select 3Google Cloud Platform

Your company stores sensitive customer information in Cloud Storage buckets. To comply with regulatory requirements, you need to ensure that this data is encrypted, access is restricted to authorized users only, and no sensitive data is accidentally exposed. Which combination of security measures should you implement to meet these requirements?

  1. A

    Enable Bucket Policy Only to enforce IAM policies on the Cloud Storage bucket.

  2. B

    Use Customer-Managed Encryption Keys (CMEK) to encrypt the data in the bucket.

  3. C

    Set the Cloud Storage bucket to 'public' for easier access control.

  4. D

    Implement VPC Service Controls to prevent unauthorized data exfiltration.

  5. E

    Enable Object Versioning on the bucket to track changes and accidental deletions.

Show answer and explanation

Correct answers: A, B, D

Explanation

To protect sensitive data and comply with regulatory requirements, you need to implement multiple layers of security. Enabling Bucket Policy Only restricts access to authorized users, Customer-Managed Encryption Keys (CMEK) ensures encryption compliance, and VPC Service Controls prevent unauthorized data exfiltration. These combined measures address access control, encryption, and data loss prevention effectively.

  • A. Correct.

    Enabling Bucket Policy Only ensures that only IAM policies are used for access control, which helps restrict access to authorized users.

  • B. Correct.

    Using Customer-Managed Encryption Keys (CMEK) allows you to control the encryption keys and ensures compliance with encryption requirements.

  • C. Incorrect.

    Setting the bucket to 'public' would expose sensitive data and violate security best practices and regulatory requirements.

  • D. Correct.

    Implementing VPC Service Controls helps define secure perimeters and prevents unauthorized data exfiltration, which is essential for data protection.

  • E. Incorrect.

    While Object Versioning is useful for tracking changes and accidental deletions, it does not directly address encryption, access control, or data exposure risks.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam