Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 472 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 472

Select 3Google Cloud Platform

Your organization is designing a cloud infrastructure to process sensitive financial data. The system requires high availability, encryption at rest, and secure connectivity between compute resources and storage. Which Google Cloud services and configurations should you recommend to meet the requirements?

  1. A

    Use Compute Engine instances with local SSDs for high performance and encrypt the data using customer-managed encryption keys (CMEK).

  2. B

    Enable IAM roles and policies to restrict access to the storage buckets.

  3. C

    Use Cloud VPN to establish a secure connection between on-premises infrastructure and Google Cloud.

  4. D

    Use Cloud Storage with Object Versioning enabled and enforce encryption using a Google-managed key.

  5. E

    Deploy a global load balancer to ensure high availability and distribute traffic across regions.

  6. F

    Enable VPC Service Controls to protect against unauthorized data exfiltration.

Show answer and explanation

Correct answers: A, B, F

Explanation

The requirements specify high availability, encryption at rest, and secure connectivity between compute and storage. Using Compute Engine with CMEK ensures encryption at rest with customer control over keys. IAM roles and policies restrict access to storage buckets, meeting security requirements. VPC Service Controls add an extra layer of security to prevent unauthorized data exfiltration. Other options like load balancers and Cloud VPN are useful but do not directly address the requirements for encryption or secure communication between compute and storage resources.

  • A. Correct.

    This option meets the requirements for high performance and encryption at rest using customer-managed encryption keys (CMEK), which gives you full control over your encryption keys.

  • B. Correct.

    IAM roles and policies are essential for restricting access to sensitive financial data stored in Google Cloud Storage buckets, ensuring proper access controls.

  • C. Incorrect.

    While Cloud VPN establishes a secure connection between on-premises systems and Google Cloud, this is not relevant for securing communication between compute resources and storage within Google Cloud itself.

  • D. Incorrect.

    Using Cloud Storage with Object Versioning and Google-managed keys provides encryption, but it does not meet the requirement for customer-managed encryption keys or address secure connectivity between resources.

  • E. Incorrect.

    A global load balancer ensures high availability for traffic distribution but does not address encryption or secure connectivity between compute and storage resources.

  • F. Correct.

    VPC Service Controls provide an additional layer of security, preventing unauthorized data exfiltration for sensitive data, which is crucial for financial data.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam