Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 370 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 370

Select 3Google Cloud Platform

You are tasked with designing a secure machine learning (ML) training environment for a financial services company. The company uses a combination of IaaS and PaaS services on Google Cloud for hosting ML models and training data. Which of the following actions should you take to ensure the security of the training environment?

  1. A

    Use customer-managed encryption keys (CMEK) to encrypt sensitive training data stored on Cloud Storage.

  2. B

    Enable VPC Service Controls to restrict data exfiltration from the training environment.

  3. C

    Disable IAM roles for Compute Engine instances hosting the training models to prevent identity mismanagement.

  4. D

    Configure private IPs and restrict public access for Cloud AI Platform training jobs.

  5. E

    Rely on the default Google-managed encryption and avoid additional encryption layers for training data.

Show answer and explanation

Correct answers: A, B, D

Explanation

To secure ML training environments hosted on Google Cloud, especially for sensitive industries like financial services, it is critical to use customer-managed encryption keys (CMEK) for encryption, implement VPC Service Controls to prevent data exfiltration, and restrict public access to training environments by configuring private IPs. These measures help ensure data confidentiality and compliance with regulatory standards while maintaining the integrity of the training process.

  • A. Correct.

    Customer-managed encryption keys (CMEK) provide better control over encryption, allowing the organization to manage the lifecycle of keys and comply with strict compliance requirements, especially important for sensitive financial data.

  • B. Correct.

    VPC Service Controls help prevent data exfiltration by enforcing secure perimeters around sensitive resources, which is critical for protecting financial data during training.

  • C. Incorrect.

    Disabling IAM roles for Compute Engine instances would prevent them from accessing necessary resources, potentially breaking the training process. Instead, you should follow the principle of least privilege to assign appropriate roles.

  • D. Correct.

    Configuring private IPs and restricting public access ensures that the training environment is not exposed to the internet, reducing the risk of unauthorized access.

  • E. Incorrect.

    Relying solely on default Google-managed encryption might not meet the company's compliance or security requirements. Adding an additional layer of encryption, like CMEK, is more secure for sensitive financial data.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam