Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 381 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 381

Select 3Google Cloud Platform

You are designing a Vertex AI solution for your organization to train and deploy machine learning models. The organization requires strict security measures to ensure that sensitive data used during training is protected, and the deployed model cannot be accessed by unauthorized users. Which of the following security controls should you implement to meet these requirements?

  1. A

    Enable private endpoints for Vertex AI endpoints to restrict access to the deployed model within the organization’s VPC.

  2. B

    Use customer-managed encryption keys (CMEK) to encrypt sensitive data used in model training.

  3. C

    Configure fine-grained IAM roles to control access to Vertex AI resources for different teams within the organization.

  4. D

    Store training data in a public Cloud Storage bucket to ensure easy access during the model training process.

  5. E

    Enable Vertex AI dataset monitoring to automatically detect and prevent unauthorized access to training datasets.

Show answer and explanation

Correct answers: A, B, C

Explanation

To secure a Vertex AI solution, you need to implement a comprehensive security strategy. Enabling private endpoints ensures that your deployed models are only accessible within your secure network. Using CMEK for sensitive data encryption gives you control over encryption keys, aligning with common security compliance requirements. Configuring fine-grained IAM roles ensures that only authorized individuals have access to Vertex AI resources. Storing training data in public buckets or relying on a non-existent feature like 'dataset monitoring' would compromise security and fail to meet the organization's requirements.

  • A. Correct.

    Enabling private endpoints ensures that access to the deployed model endpoint is confined to the organization’s network, preventing unauthorized external access.

  • B. Correct.

    Using customer-managed encryption keys (CMEK) provides you with control over the encryption keys used to protect sensitive data during model training, aligning with strict security requirements.

  • C. Correct.

    Fine-grained IAM roles allow you to define specific permissions for Vertex AI resources, ensuring that only authorized users and teams have access to sensitive data and models.

  • D. Incorrect.

    Storing training data in a public Cloud Storage bucket exposes the data to potential unauthorized access and does not align with the requirement for strict security measures.

  • E. Incorrect.

    Vertex AI does not currently provide a feature called 'dataset monitoring' for detecting and preventing unauthorized access. Instead, data access should be secured with proper IAM roles and encryption.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam