Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 482 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 482

Select 3Google Cloud Platform

Your organization is deploying a web application on Google Cloud using Compute Engine instances, Google Cloud Storage, and Cloud Load Balancing. As a Professional Cloud Security Engineer, you are tasked with ensuring that the shared responsibility model is followed correctly. Which of the following responsibilities falls under your organization’s scope?

  1. A

    Configuring IAM policies to restrict access to the Compute Engine instances.

  2. B

    Ensuring that Google Cloud's physical data centers are secure and compliant with industry standards.

  3. C

    Keeping the operating system on the Compute Engine instances up to date with patches.

  4. D

    Managing the availability and reliability of Cloud Load Balancing as a service.

  5. E

    Encrypting sensitive data stored in Google Cloud Storage using customer-managed encryption keys (CMEK).

Show answer and explanation

Correct answers: A, C, E

Explanation

In the shared responsibility model, Google Cloud manages the security of the cloud infrastructure, including physical data centers and managed services. However, customers are responsible for securing their data, managing access controls, and maintaining the security of resources they control, such as Compute Engine instances and encryption configurations.

  • A. Correct.

    Configuring IAM policies is your organization's responsibility because it involves managing access to your resources and is part of the customer's role in the shared responsibility model.

  • B. Incorrect.

    Ensuring the physical security and compliance of Google Cloud's data centers is Google's responsibility, not the customer’s, as part of the shared responsibility model.

  • C. Correct.

    Keeping the operating system patched on Compute Engine instances is the customer’s responsibility because the instances are under customer control.

  • D. Incorrect.

    Managing the availability and reliability of Cloud Load Balancing is Google Cloud’s responsibility as it is a managed service provided by Google.

  • E. Correct.

    Encrypting sensitive data with CMEK is the customer’s responsibility since it involves the use of customer-managed keys and securing their data.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam