Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 479 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 479

Select 3Google Cloud Platform

Your company has moved its e-commerce platform to Google Cloud. As the security engineer, you are tasked with ensuring that the platform complies with security and data protection standards. When evaluating the shared responsibility model for your deployment, which of the following responsibilities fall under your company’s scope?

  1. A

    Configuring IAM roles and permissions for platform users.

  2. B

    Ensuring physical security of the Google Cloud data centers.

  3. C

    Managing the encryption of data stored in Cloud Storage buckets.

  4. D

    Patching the underlying infrastructure of Google Compute Engine VMs.

  5. E

    Configuring firewall rules to control traffic to Google Compute Engine instances.

Show answer and explanation

Correct answers: A, C, E

Explanation

In the shared responsibility model, Google Cloud handles the security of the infrastructure, such as physical security, networking, and the hypervisor. Customers are responsible for securing their use of Google Cloud services, including managing IAM permissions, configuring network security settings like firewalls, and ensuring proper encryption of their data. Understanding these distinctions is critical for maintaining a secure cloud environment.

  • A. Correct.

    Configuring IAM roles and permissions is part of the customer’s responsibility in the shared responsibility model, as they manage access to their resources.

  • B. Incorrect.

    Google is responsible for the physical security of its data centers, including lock-and-key access, surveillance, and environmental controls.

  • C. Correct.

    Managing encryption of data stored in Cloud Storage, such as enabling customer-managed encryption keys (CMEK), is the customer's responsibility.

  • D. Incorrect.

    Patching the underlying infrastructure, such as the hypervisor and physical servers, is managed by Google as part of their responsibility in the shared responsibility model.

  • E. Correct.

    Configuring firewall rules to control traffic is the customer’s responsibility because it involves managing how their resources are accessed and protected.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam