Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 481 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 481

Select 3Google Cloud Platform

Your company is migrating a critical application to Google Cloud. The application processes sensitive customer data and must adhere to strict compliance requirements. As the security engineer, you are tasked with evaluating the shared responsibility model for securing this application. Which responsibilities fall under the customer’s scope in this model?

  1. A

    Configuring Identity and Access Management (IAM) roles and permissions for users in the project

  2. B

    Ensuring the physical security of Google Cloud data centers hosting the application

  3. C

    Encrypting sensitive data stored in Google Cloud Storage buckets

  4. D

    Managing the security of the operating system on Compute Engine instances used by the application

  5. E

    Monitoring and patching vulnerabilities in Google-managed services, such as BigQuery

Show answer and explanation

Correct answers: A, C, D

Explanation

The shared responsibility model in Google Cloud delineates the security responsibilities between Google and the customer. Google is responsible for the security 'of' the cloud, which includes infrastructure, physical security, and managed services. Customers, on the other hand, are responsible for security 'in' the cloud, which includes configuring access controls, managing data encryption, and securing workloads they deploy, such as Compute Engine instances. Understanding these responsibilities ensures that both Google and the customer work together to maintain a strong security posture.

  • A. Correct.

    Correct. Configuring IAM roles and permissions is a customer responsibility under the shared responsibility model, as it involves managing access to resources within the customer’s project.

  • B. Incorrect.

    Incorrect. Physical security of Google Cloud data centers is the responsibility of Google Cloud as part of the shared responsibility model.

  • C. Correct.

    Correct. Encrypting sensitive data at rest or in transit in customer-controlled resources, such as Cloud Storage buckets, is the customer’s responsibility.

  • D. Correct.

    Correct. When using Compute Engine, managing the security of the operating system and applying patches is the customer’s responsibility.

  • E. Incorrect.

    Incorrect. Monitoring and patching vulnerabilities in Google-managed services, such as BigQuery, is Google’s responsibility as part of its infrastructure and managed services.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam