Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 372 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 372

Select 4Google Cloud Platform

Your organization is building a machine learning training model hosted on Google Cloud. The team is considering using a mix of IaaS (VMs on Compute Engine) and PaaS (AI Platform Training) for different stages of the training process. As a Cloud Security Engineer, which security requirements should you recommend to ensure the protection of sensitive training data and compliance with organizational policies?

  1. A

    Enable VPC Service Controls to restrict data exfiltration from AI Platform Training and Compute Engine instances.

  2. B

    Use IAM roles to assign the least privilege required for accessing training data and resources.

  3. C

    Ensure that all training data stored in Cloud Storage is encrypted using customer-managed encryption keys (CMEK).

  4. D

    Disable network access to Compute Engine instances and AI Platform Training jobs to ensure complete isolation.

  5. E

    Use Confidential VMs for Compute Engine to secure data in use during training processes.

Show answer and explanation

Correct answers: A, B, C, E

Explanation

When building and securing training models hosted on IaaS and PaaS, it is essential to address security requirements such as data exfiltration prevention, least privilege access, data encryption, and securing data in use. VPC Service Controls, IAM policies, CMEK encryption, and Confidential VMs collectively ensure a robust security posture while maintaining the functionality of training processes. Disabling network access entirely would disrupt the services and is not a viable solution.

  • A. Correct.

    Enabling VPC Service Controls helps prevent data exfiltration by restricting services' access to resources outside the defined perimeter. This is a critical measure for both PaaS and IaaS-hosted training models.

  • B. Correct.

    Using IAM roles with the principle of least privilege minimizes the risk of unauthorized access to training data and resources.

  • C. Correct.

    Encrypting training data with customer-managed encryption keys (CMEK) provides greater control over the encryption and decryption processes, ensuring compliance with organizational security policies.

  • D. Incorrect.

    Disabling all network access to Compute Engine instances and AI Platform Training jobs would prevent the training process from functioning properly, as it would block necessary communication between resources.

  • E. Correct.

    Confidential VMs protect data in use within Compute Engine by leveraging secure enclaves, which is especially important for sensitive workloads like training models.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam