Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 374 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 374

Select 3Google Cloud Platform

You are tasked with deploying a machine learning training model on Google Cloud. The model will be hosted using a combination of IaaS (Compute Engine) and PaaS (AI Platform Training). To ensure the security of the deployment, which of the following actions should you take?

  1. A

    Ensure that Compute Engine instances have the minimum required IAM roles for accessing Cloud Storage.

  2. B

    Activate VPC Service Controls to protect data movement between AI Platform Training and other services.

  3. C

    Use default service accounts on Compute Engine instances to simplify authentication processes.

  4. D

    Encrypt sensitive training data at rest using Cloud Key Management Service (KMS).

  5. E

    Enable public IP addresses for Compute Engine instances to maximize connectivity for model training.

Show answer and explanation

Correct answers: A, B, D

Explanation

To secure IaaS and PaaS-hosted training models, it is essential to follow best practices, such as implementing the principle of least privilege by restricting IAM roles, using VPC Service Controls to protect inter-service communication, and encrypting sensitive data at rest. Avoid using default service accounts with broad permissions or exposing resources unnecessarily via public IPs, as these practices can increase the risk of security breaches.

  • A. Correct.

    Ensuring that Compute Engine instances have the minimum required IAM roles is a fundamental security practice to follow the principle of least privilege, reducing the risk of unauthorized access.

  • B. Correct.

    Activating VPC Service Controls adds a security boundary around resources, preventing data exfiltration and securing interactions between services like AI Platform Training and Cloud Storage.

  • C. Incorrect.

    Using default service accounts is not recommended as they often have overly broad permissions, which goes against the principle of least privilege and increases the attack surface.

  • D. Correct.

    Encrypting sensitive training data at rest using Cloud KMS ensures that data is protected even if storage is compromised, aligning with best practices for securing sensitive information.

  • E. Incorrect.

    Enabling public IP addresses for Compute Engine instances increases the attack surface and exposes the infrastructure to external threats, which should be avoided unless absolutely necessary.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam