Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 434 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 434

Select 3Google Cloud Platform

Your organization has recently detected suspicious activity on a Compute Engine VM that is part of a production system. As a Professional Cloud Security Engineer, you are tasked with investigating and remediating the incident while ensuring minimal disruption to the production environment. Which actions should you take to address this situation effectively?

  1. A

    Use Cloud Logging to review logs for the affected VM to identify any suspicious activity or unauthorized access.

  2. B

    Immediately stop the affected VM to prevent further damage and delete associated logs for privacy purposes.

  3. C

    Quarantine the affected VM by isolating it in a separate VPC network to prevent lateral movement of the threat.

  4. D

    Create a snapshot of the affected VM's disk for forensic analysis before making any changes to the VM.

  5. E

    Disable all user accounts associated with the affected VM to ensure no further access is possible.

Show answer and explanation

Correct answers: A, C, D

Explanation

In the event of a security incident, it is important to follow a systematic approach to investigate and remediate the issue. Reviewing logs helps identify the nature of the threat, quarantining the VM prevents further damage, and creating a snapshot preserves evidence for forensic analysis. These steps ensure an effective response while minimizing disruption to production systems and preserving critical evidence for further analysis.

  • A. Correct.

    Cloud Logging provides detailed insights into the activities of the VM, which is crucial for understanding the nature of the suspected security incident.

  • B. Incorrect.

    Stopping the VM and deleting logs is not a best practice. Deleting logs removes critical evidence and stopping the VM could disrupt production unnecessarily without first assessing the impact.

  • C. Correct.

    Quarantining the affected VM prevents the threat from spreading to other resources while allowing for further investigation and containment.

  • D. Correct.

    Creating a snapshot of the VM's disk ensures that you have an immutable copy of the current state of the system for forensic analysis, which is critical for understanding the root cause of the incident.

  • E. Incorrect.

    Disabling all user accounts associated with the VM is an overly broad action that can affect users unrelated to the incident, and it is not recommended without first understanding the scope of the issue.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam