Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 435 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 435

Select 4Google Cloud Platform

Your organization recently detected suspicious activity within its Google Cloud environment, including unusual spikes in network traffic and unauthorized API calls. As a Professional Cloud Security Engineer, you are tasked with investigating and responding to this incident. Which steps should you take to ensure the incident is logged, monitored, and remediated effectively?

  1. A

    Enable VPC Flow Logs for all VPC networks to capture network traffic details.

  2. B

    Set up a Cloud Pub/Sub topic to receive Security Command Center findings and automatically trigger an incident response workflow.

  3. C

    Grant the affected service accounts the Owner role to collect more data for investigation.

  4. D

    Review Cloud Audit Logs for unusual activity and filter logs based on specific service accounts or IP addresses.

  5. E

    Use Cloud Functions to automate remediation actions, such as blocking suspicious IPs or disabling compromised service accounts.

Show answer and explanation

Correct answers: A, B, D, E

Explanation

Effective logging, monitoring, and remediation of security incidents in Google Cloud require multiple coordinated steps. Enabling VPC Flow Logs provides visibility into network traffic, while reviewing Cloud Audit Logs helps pinpoint suspicious activity. Automating workflows via Cloud Pub/Sub and Cloud Functions expedites detection and response processes. However, granting excessive permissions to service accounts violates best practices and should be avoided.

  • A. Correct.

    Enabling VPC Flow Logs is crucial for monitoring network traffic and identifying anomalous patterns. This step helps in understanding the scope of the incident.

  • B. Correct.

    Cloud Pub/Sub integration with Security Command Center can automate the detection and response process, making it a critical component of incident response.

  • C. Incorrect.

    Granting the Owner role to affected service accounts increases the scope of permissions unnecessarily, which goes against the principle of least privilege and can exacerbate the security incident.

  • D. Correct.

    Cloud Audit Logs provide detailed records of API calls and user activity, which are essential for tracing unauthorized access or operations during an incident investigation.

  • E. Correct.

    Automating remediation actions using Cloud Functions ensures a swift and reliable response to security incidents, such as blocking malicious activity or isolating affected resources.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam