Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 404 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 404

Select 2Google Cloud Platform

Your organization uses Google Cloud to host its applications and has a policy requiring all virtual machines (VMs) and container images to follow security best practices, including hardening and regular patching. You need to implement an automated process to ensure all VM images and container images are compliant with the policy before deployment. Which of the following actions should you take? (Choose TWO)

  1. A

    Use Google Cloud Build to create and validate container images against a hardened base image.

  2. B

    Enable VM Manager to automate patch compliance reporting and patch deployment for virtual machines.

  3. C

    Manually review all container images in the Container Registry for vulnerabilities before deployment.

  4. D

    Use Deployment Manager templates to enforce patching policies on already deployed virtual machines.

  5. E

    Implement Binary Authorization to ensure only trusted container images are deployed.

Show answer and explanation

Correct answers: A, B

Explanation

To automate the creation and maintenance of secure VM and container images, Google Cloud Build can be used to create and validate compliant container images, while VM Manager automates patch compliance and deployment for virtual machines. These tools align with Google Cloud's best practices for automating image creation and maintenance. Other options, such as manual review or using Binary Authorization, address different aspects of the security process but do not fulfill the requirements for automation.

  • A. Correct.

    This is correct. Google Cloud Build can automate the creation and validation of container images, ensuring they are based on a hardened base image and meet security compliance requirements.

  • B. Correct.

    This is correct. VM Manager automates patch compliance reporting and deployment, ensuring virtual machines are regularly updated and secure.

  • C. Incorrect.

    This is incorrect. Manually reviewing container images is inefficient and prone to error. Automated vulnerability scanning should be used instead.

  • D. Incorrect.

    This is incorrect. Deployment Manager templates are not designed for enforcing patching policies; VM Manager is a more appropriate tool for this purpose.

  • E. Incorrect.

    This is incorrect. While Binary Authorization is useful for verifying trusted container images during deployment, it does not automate the creation or maintenance of images.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam