Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 376 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 376

Select 3Google Cloud Platform

You are a Professional Cloud Security Engineer tasked with securing a Vertex AI environment used by your organization. The team uses Vertex AI to train machine learning models with sensitive customer data. Which of the following actions should you take to ensure the security of data and models in this environment?

  1. A

    Enable Customer-Managed Encryption Keys (CMEK) for Vertex AI resources.

  2. B

    Set up a private endpoint for Vertex AI to prevent access over the public internet.

  3. C

    Disable logging features for Vertex AI pipelines to avoid storing sensitive information.

  4. D

    Use Identity and Access Management (IAM) roles to enforce least privilege access.

  5. E

    Ensure all datasets are stored in public Cloud Storage buckets for easier collaboration.

Show answer and explanation

Correct answers: A, B, D

Explanation

To secure a Vertex AI environment, it is critical to implement data encryption using CMEK, restrict access using private endpoints, and enforce least privilege access through IAM roles. These measures collectively ensure the security of data and models in the environment. Disabling logging or storing sensitive data in public buckets would compromise security, making those options inappropriate.

  • A. Correct.

    Enabling Customer-Managed Encryption Keys (CMEK) ensures data encryption is controlled by the organization and adds an additional layer of security.

  • B. Correct.

    Setting up a private endpoint for Vertex AI prevents traffic from being exposed over the public internet, reducing the attack surface.

  • C. Incorrect.

    Disabling logging features is not recommended because logs are useful for auditing and troubleshooting. Instead, sensitive information in logs should be carefully managed.

  • D. Correct.

    Using IAM roles to enforce least privilege access ensures that only authorized individuals or services can access Vertex AI resources, aligning with security best practices.

  • E. Incorrect.

    Storing datasets in public Cloud Storage buckets is a major security risk as it exposes sensitive data to unauthorized access. Private or restricted buckets should be used instead.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam