Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 379 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 379

Select 3Google Cloud Platform

Your organization is using Vertex AI for training machine learning models. You need to ensure that sensitive data used during training is protected and that access to the Vertex AI pipelines is restricted following the principle of least privilege. What steps should you take to implement these security controls?

  1. A

    Use Customer-Managed Encryption Keys (CMEK) to encrypt data stored in Vertex AI.

  2. B

    Grant the Vertex AI Service Agent role to all users in your organization to simplify access management.

  3. C

    Enable private endpoints for Vertex AI to restrict access to authorized networks only.

  4. D

    Leverage IAM roles to grant granular permissions to Vertex AI resources.

  5. E

    Use public buckets for training data to ensure easy access for developers and training pipelines.

Show answer and explanation

Correct answers: A, C, D

Explanation

To implement security controls for Vertex AI, it's critical to ensure that sensitive data is encrypted, access is restricted to authorized networks, and permissions are granted on a need-to-know basis. Using CMEK allows you to manage encryption keys securely, private endpoints restrict network access, and IAM roles enforce proper access control. Avoid practices like granting broad access or using public buckets, as they pose significant security risks.

  • A. Correct.

    Using Customer-Managed Encryption Keys (CMEK) ensures that sensitive data stored in Vertex AI is encrypted with a key that you control, providing an additional layer of security.

  • B. Incorrect.

    Granting the Vertex AI Service Agent role to all users violates the principle of least privilege, as it provides unnecessary access to all users in your organization.

  • C. Correct.

    Enabling private endpoints for Vertex AI restricts access to the service to authorized networks, ensuring that only trusted systems can connect.

  • D. Correct.

    Leveraging IAM roles allows you to enforce the principle of least privilege by granting users or services only the permissions they need for specific Vertex AI resources.

  • E. Incorrect.

    Using public buckets for training data is not secure, as it exposes sensitive data to unauthorized access.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam