Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 312 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 312

Select 3Google Cloud Platform

Your organization uses Compute Engine instances to run critical workloads. You want to ensure that unauthorized access to sensitive instance metadata, such as API tokens, is prevented. Which of the following security measures should you implement to protect and manage instance metadata effectively?

  1. A

    Enable the Metadata Query Headers feature to require specific request headers for metadata access.

  2. B

    Disable the default service account attached to the instance to prevent metadata access.

  3. C

    Restrict the metadata server access by using a network firewall rule.

  4. D

    Use IAM roles and permissions to control access to the metadata server.

  5. E

    Enable Shielded VM to encrypt metadata requests.

Show answer and explanation

Correct answers: A, C, D

Explanation

Protecting instance metadata is critical for securing sensitive information like API tokens and service account credentials. The Metadata Query Headers feature adds security to metadata requests, while restricting network access and using IAM roles ensure only authorized access to metadata. Disabling the default service account or enabling Shielded VM does not directly address metadata protection.

  • A. Correct.

    Enabling the Metadata Query Headers feature ensures that metadata requests need specific headers, preventing potential exploitation like Server-Side Request Forgery (SSRF).

  • B. Incorrect.

    Disabling the default service account does not inherently protect metadata access and may disrupt workloads that rely on the default service account for operations.

  • C. Correct.

    Restricting metadata server access using network firewall rules prevents unauthorized network paths from accessing the metadata server.

  • D. Correct.

    Using IAM roles and permissions to control access ensures that only authorized identities can retrieve sensitive metadata like API tokens.

  • E. Incorrect.

    Enabling Shielded VM is a security feature for protecting the boot process and ensuring instance integrity but does not specifically protect metadata requests.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam