Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 373 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 373

Select 3Google Cloud Platform

You are tasked with deploying a machine learning model for training on Google Cloud. The model will be hosted across both IaaS (Compute Engine) and PaaS (AI Platform Training). Which of the following steps should you take to ensure the security of the training environment?

  1. A

    Use VPC Service Controls to restrict data movement for the AI Platform Training environment.

  2. B

    Enable Shielded VM features for Compute Engine instances hosting the training model.

  3. C

    Store API keys in the training code for easy access during training jobs.

  4. D

    Configure IAM roles to grant least privilege access to developers and training jobs.

  5. E

    Disable all logging features to avoid performance overhead during training.

Show answer and explanation

Correct answers: A, B, D

Explanation

Securing IaaS and PaaS-hosted training environments involves implementing multiple layers of security. For IaaS (Compute Engine), enabling Shielded VM features protects the integrity of the instances. For PaaS (AI Platform Training), VPC Service Controls help prevent unauthorized data exfiltration. Additionally, applying IAM roles with least privilege ensures secure access management. Avoid storing sensitive credentials in code and disabling monitoring tools, as these practices compromise security and visibility.

  • A. Correct.

    Using VPC Service Controls can help restrict data movement and protect sensitive data in the PaaS environment, such as AI Platform Training, by defining security perimeters.

  • B. Correct.

    Enabling Shielded VM features on Compute Engine protects against rootkits and other low-level attacks, ensuring the integrity of the IaaS-hosted training environment.

  • C. Incorrect.

    Storing API keys in the training code is insecure and can lead to credential leaks. Best practices recommend using tools like Secret Manager or Application Default Credentials.

  • D. Correct.

    Configuring IAM roles with least privilege ensures that users and services only have access to the resources they need, reducing the risk of unauthorized access or accidental changes.

  • E. Incorrect.

    Disabling logging features is not recommended as it hinders the ability to monitor and audit activities for security and compliance purposes.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam