Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 405 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 405

Select 3Google Cloud Platform

Your organization uses Google Cloud to host applications in both virtual machine instances and containers. To ensure compliance with security policies, you need to automate the creation of hardened VM images and container images, as well as manage patching for virtual machines. Which of the following approaches should you implement to meet these requirements?

  1. A

    Use Google Cloud's OS Config to automate patch management for VM instances.

  2. B

    Integrate Cloud Build with Container Analysis to automate vulnerability scanning for container images.

  3. C

    Manually update VM images and container images with the latest patches and vulnerabilities every month.

  4. D

    Use an Infrastructure as Code (IaC) tool like Terraform to provision hardened VM images using pre-configured base images.

  5. E

    Enable automatic updates for the operating system in the Compute Engine VM instance settings.

Show answer and explanation

Correct answers: A, B, D

Explanation

To automate the creation and maintenance of secure VM and container images, you need to leverage tools and services that provide automation and scalability. OS Config automates patch management for VMs, while Cloud Build and Container Analysis handle container image vulnerability scanning. Using an IaC tool like Terraform ensures consistent provisioning of hardened images. Manual updates and enabling automatic OS updates alone do not provide comprehensive automation or address all aspects of the security requirements.

  • A. Correct.

    Correct: Google Cloud's OS Config allows you to automate patch management, ensuring that VM instances stay up to date with the latest security patches without manual intervention.

  • B. Correct.

    Correct: Cloud Build and Container Analysis can be integrated to automate vulnerability scanning for container images, ensuring that insecure images are flagged during the build process.

  • C. Incorrect.

    Incorrect: Manually updating images is error-prone and inefficient. Automation is preferred for scalability and consistency in maintaining security.

  • D. Correct.

    Correct: Using an Infrastructure as Code (IaC) tool like Terraform to provision hardened VM images ensures that they are built using pre-configured base images that adhere to organizational security policies.

  • E. Incorrect.

    Incorrect: While enabling automatic OS updates can help with patching, it does not address the automation of container image creation or ensure compliance with hardened image requirements.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam