Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 304 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 304

Select 3Google Cloud Platform

You are a security engineer at an organization that uses Google Cloud. You need to restrict access to sensitive data stored in BigQuery, Cloud Storage, and Cloud SQL while ensuring that only authorized users can access specific datasets, buckets, or instances. What are the most appropriate actions to achieve this?

  1. A

    Assign predefined roles such as 'roles/storage.objectViewer' or 'roles/bigquery.dataViewer' to specific users or groups.

  2. B

    Use VPC Service Controls to define service perimeters around your Google Cloud data services to prevent unauthorized access.

  3. C

    Encrypt the data in BigQuery, Cloud Storage, and Cloud SQL with Customer-Managed Encryption Keys (CMEK) and share the key with all users.

  4. D

    Configure IAM Conditions to enforce access restrictions based on attributes like time, IP address, or resource name.

  5. E

    Grant the 'roles/owner' role at the project level to ensure all authorized users can access the required resources.

Show answer and explanation

Correct answers: A, B, D

Explanation

To restrict access to Google Cloud data services like BigQuery, Cloud Storage, and Cloud SQL, it is essential to follow the principle of least privilege by assigning only the necessary predefined roles to users. Additionally, you can enhance security by implementing VPC Service Controls to create secure perimeters and using IAM Conditions for fine-grained access control. Avoid overly permissive roles or sharing encryption keys indiscriminately, as these practices can expose your resources to unauthorized access.

  • A. Correct.

    Correct: Assigning predefined roles such as 'roles/storage.objectViewer' or 'roles/bigquery.dataViewer' provides the least-privilege access required for users to access specific data services.

  • B. Correct.

    Correct: VPC Service Controls help create a secure perimeter around your data services, preventing unauthorized access from outside the defined perimeter.

  • C. Incorrect.

    Incorrect: While CMEK enhances encryption, sharing the key with all users does not restrict access and could lead to unauthorized access.

  • D. Correct.

    Correct: IAM Conditions allow you to implement fine-grained access control, restricting access based on specific attributes like time, IP address, or resource name.

  • E. Incorrect.

    Incorrect: Granting the 'roles/owner' role at the project level provides excessive permissions, violating the principle of least privilege.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam