Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 473 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 473

Select 4Google Cloud Platform

Your organization is migrating a critical application from an on-premises data center to Google Cloud. The application processes sensitive financial data and has strict compliance requirements. It also requires high availability, low-latency access to a database, and secure network connectivity between the application and external partners. Which Google Cloud services and configurations should you prioritize to meet the technical needs of the application?

  1. A

    Use Google Kubernetes Engine (GKE) to deploy the application workloads and ensure high availability.

  2. B

    Utilize Cloud SQL with customer-managed encryption keys (CMEK) for storing the financial data.

  3. C

    Configure a Virtual Private Cloud (VPC) with Private Google Access and Firewall Rules for secure network connectivity.

  4. D

    Deploy the application on Compute Engine preemptible virtual machines to minimize costs.

  5. E

    Implement Cloud Storage with standard storage class for storing compliance-related audit logs.

  6. F

    Set up a Dedicated Interconnect for secure, low-latency connectivity to external partners.

Show answer and explanation

Correct answers: A, B, C, F

Explanation

To meet the technical needs of the application, you need to focus on solutions that ensure high availability, secure processing of sensitive data, and compliance with regulatory requirements. GKE provides a scalable and highly available platform for workloads. Cloud SQL with CMEK ensures data security and compliance. A VPC with secure configurations protects network traffic, and Dedicated Interconnect enables reliable communication with external partners. Preemptible VMs and standard Cloud Storage do not align with the application's critical and compliance-related requirements.

  • A. Correct.

    Google Kubernetes Engine (GKE) is well-suited for deploying containerized workloads with high availability. It provides features such as auto-scaling, multi-zone clusters, and built-in security measures, making it a good option for critical applications.

  • B. Correct.

    Cloud SQL with customer-managed encryption keys (CMEK) ensures that sensitive financial data is encrypted with keys that you control, meeting compliance requirements while providing a managed and reliable database service.

  • C. Correct.

    Configuring a Virtual Private Cloud (VPC) with Private Google Access and Firewall Rules enhances network security by restricting access to your resources and ensuring only authorized traffic can communicate with your application.

  • D. Incorrect.

    Preemptible virtual machines are cost-effective but not suitable for critical applications requiring high availability, as they can be terminated by Google Cloud with little notice.

  • E. Incorrect.

    Cloud Storage with standard storage class is not optimized for compliance-related audit logs. For compliance purposes, you would typically use log services like Cloud Logging or archival storage with appropriate retention policies.

  • F. Correct.

    A Dedicated Interconnect provides secure, high-bandwidth, and low-latency connectivity, which is ideal for critical communications with external partners.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam