
Obtain the Professional-Cloud-Security-Engineer PDF Dumps Get 100% Outcomes Exam Questions For You To Pass
Professional-Cloud-Security-Engineer Exam Dumps Contains FREE Real Quesions from the Actual Exam
NEW QUESTION # 76
Your company is using Cloud Dataproc for its Spark and Hadoop jobs. You want to be able to create, rotate, and destroy symmetric encryption keys used for the persistent disks used by Cloud Dataproc. Keys can be stored in the cloud.
What should you do?
- A. Use the Cloud Key Management Service to manage the key encryption key (KEK).
- B. Use customer-supplied encryption keys to manage the data encryption key (DEK).
- C. Use the Cloud Key Management Service to manage the data encryption key (DEK).
- D. Use customer-supplied encryption keys to manage the key encryption key (KEK).
Answer: C
NEW QUESTION # 77
An application running on a Compute Engine instance needs to read data from a Cloud Storage bucket. Your team does not allow Cloud Storage buckets to be globally readable and wants to ensure the principle of least privilege.
Which option meets the requirement of your team?
- A. Encrypt the data in the Cloud Storage bucket using Cloud KMS, and allow the application to decrypt the data with the KMS key.
- B. Use a service account with read-only access to the Cloud Storage bucket, and store the credentials to the service account in the config of the application on the Compute Engine instance.
- C. Create a Cloud Storage ACL that allows read-only access from the Compute Engine instance's IP address and allows the application to read from the bucket without credentials.
- D. Use a service account with read-only access to the Cloud Storage bucket to retrieve the credentials from the instance metadata.
Answer: D
NEW QUESTION # 78
A customer's data science group wants to use Google Cloud Platform (GCP) for their analytics workloads.
Company policy dictates that all data must be company-owned and all user authentications must go through their own Security Assertion Markup Language (SAML) 2.0 Identity Provider (IdP). The Infrastructure Operations Systems Engineer was trying to set up Cloud Identity for the customer and realized that their domain was already being used by G Suite.
How should you best advise the Systems Engineer to proceed with the least disruption?
- A. Ask Google to provision the data science manager's account as a Super Administrator in the existing domain.
- B. Ask customer's management to discover any other uses of Google managed services, and work with the existing Super Administrator.
- C. Register a new domain name, and use that for the new Cloud Identity domain.
- D. Contact Google Support and initiate the Domain Contestation Process to use the domain name in your new Cloud Identity domain.
Answer: A
NEW QUESTION # 79
A customer wants to make it convenient for their mobile workforce to access a CRM web interface that is hosted on Google Cloud Platform (GCP). The CRM can only be accessed by someone on the corporate network. The customer wants to make it available over the internet.
Your team requires an authentication layer in front of the application that supports two-factor authentication Which GCP product should the customer implement to meet these requirements?
- A. Cloud VPN
- B. Cloud Armor
- C. Cloud Endpoints
- D. Cloud Identity-Aware Proxy
Answer: A
NEW QUESTION # 80
You need to perform a vulnerability scan for an App Engine app using Cloud Security Scanner.
Upon completion of the scan, the report is not producing the expected number of webpage results. The pages in the app with mouseover menus are missing from the report. Which action should you take to make sure the scan completes and captures the menu?
- A. Modify the scan schedule to return new results.
- B. Verify the Excluded URLs.
- C. Change the scan to include additional Starting URLs.
- D. Adjust the Google account on which the scan is running.
Answer: C
Explanation:
A is not correct because the missing webpages in mouseover menu are unlikely to be explicitly excluded since they're expected to be scanned.
B is not correct because changing the scan schedule will not result in scanning of more webpages.
C is correct because Cloud Security Scanner may not be able to navigate through complex JavaScript such as a mouseover-driven multilevel menu. Specifying additional starting URLs can increase scan coverage in this scenario.
D is not correct because changing the Google account will not result in scanning of more webpages.
https://cloud.google.com/security-scanner/docs/scanning
NEW QUESTION # 81
Applications often require access to "secrets" - small pieces of sensitive data at build or run time. The administrator managing these secrets on GCP wants to keep a track of "who did what, where, and when?" within their GCP projects.
Which two log streams would provide the information that the administrator is looking for? (Choose two.)
- A. Data Access logs
- B. Agent logs
- C. VPC Flow logs
- D. Admin Activity logs
- E. System Event logs
Answer: A,D
Explanation:
Reference:
https://cloud.google.com/kms/docs/secret-management
NEW QUESTION # 82
Your company is using GSuite and has developed an application meant for internal usage on Google App Engine. You need to make sure that an external user cannot gain access to the application even when an employee's password has been compromised.
What should you do?
- A. Configure Cloud VPN between your private network and GCP.
- B. Enforce 2-factor authentication in GSuite for all users.
- C. Configure Cloud Identity-Aware Proxy for the App Engine Application.
- D. Provision user passwords using GSuite Password Sync.
Answer: B
NEW QUESTION # 83
An engineering team is launching a web application that will be public on the internet. The web application is hosted in multiple GCP regions and will be directed to the respective backend based on the URL request.
Your team wants to avoid exposing the application directly on the internet and wants to deny traffic from a specific list of malicious IP addresses Which solution should your team implement to meet these requirements?
- A. Network Load Balancing
- B. Cloud Armor
- C. SSL Proxy Load Balancing
- D. NAT Gateway
Answer: B
Explanation:
https://cloud.google.com/armor/docs/security-policy-concepts
NEW QUESTION # 84
You are responsible for protecting highly sensitive data in BigQuery. Your operations teams need access to this data, but given privacy regulations, you want to ensure that they cannot read the sensitive fields such as email addresses and first names. These specific sensitive fields should only be available on a need-to-know basis to the HR team. What should you do?
- A. Perform data redaction with the DLP API and store that data in BigQuery for later use.
- B. Perform tokenization for Pseudonymization with the DLP API and store that data in BigQuery for later use.
- C. Perform data masking with the DLP API and store that data in BigQuery for later use.
- D. Perform data inspection with the DLP API and store that data in BigQuery for later use.
Answer: D
NEW QUESTION # 85
You want to evaluate GCP for PCI compliance. You need to identify Google's inherent controls.
Which document should you review to find the information?
- A. PCI SSC Cloud Computing Guidelines
- B. Google Cloud Platform: Customer Responsibility Matrix
- C. Product documentation for Compute Engine
- D. PCI DSS Requirements and Security Assessment Procedures
Answer: B
Explanation:
Explanation
https://cloud.google.com/files/PCI_DSS_Shared_Responsibility_GCP_v32.pdf
https://services.google.com/fh/files/misc/gcp_pci_shared_responsibility_matrix_aug_2021.pdf
NEW QUESTION # 86
Your company operates an application instance group that is currently deployed behind a Google Cloud load balancer in us-central-1 and is configured to use the Standard Tier network. The infrastructure team wants to expand to a second Google Cloud region, us-east-2. You need to set up a single external IP address to distribute new requests to the instance groups in both regions.
What should you do?
- A. Create a new load balancer in us-east-2 using the Standard Tier network, and assign a static external IP address.
- B. Change the load balancer frontend configuration to use the Premium Tier network, and add the new instance group.
- C. Change the load balancer backend configuration to use network endpoint groups instead of instance groups.
- D. Create a Cloud VPN connection between the two regions, and enable Google Private Access.
Answer: C
NEW QUESTION # 87
A customer deploys an application to App Engine and needs to check for Open Web Application Security Project (OWASP) vulnerabilities.
Which service should be used to accomplish this?
- A. Google Cloud Audit Logs
- B. Forseti Security
- C. Cloud Armor
- D. Cloud Security Scanner
Answer: D
Explanation:
Explanation/Reference: https://cloud.google.com/security-scanner/
NEW QUESTION # 88
Your team sets up a Shared VPC Network where project co-vpc-prod is the host project. Your team has configured the firewall rules, subnets, and VPN gateway on the host project. They need to enable Engineering Group A to attach a Compute Engine instance to only the 10.1.1.0/24 subnet.
What should your team grant to Engineering Group A to meet this requirement?
- A. Compute Shared VPC Admin Role at the host project level.
- B. Compute Network User Role at the host project level.
- C. Compute Shared VPC Admin Role at the service project level.
- D. Compute Network User Role at the subnet level.
Answer: A
Explanation:
Reference:
https://cloud.google.com/vpc/docs/shared-vpc
NEW QUESTION # 89
A customer wants to grant access to their application running on Compute Engine to write only to a specific Cloud Storage bucket. How should you grant access?
- A. Create a user account, authenticate with the application, and grant Google Storage Admin permissions at the project leve
- B. Create a user account, authenticate with the application, and grant Google Storage Admin permissions at the bucket level.
- C. Create a service account for the application, and grant Cloud Storage Object Creator permissions at the bucket level.
- D. Create a service account for the application, and grant Cloud Storage Object Creator permissions to the project.
Answer: C
Explanation:
A is not correct because it doesn't restrict the scope to specific bucket.
B is correct because it provides the right permissions and keeps the scope limited to the bucket in question.
C is not correct because using a user account goes against the recommended best practice as it should be a machine/service account that should be handling the writing to bucket.
D is not correct because using a user account goes against the recommended best practice as it should be a machine/service account that should be handling the writing to bucket and it also widens the scope to storage wide which violates minimum required privilege rules.
https://cloud.google.com/iam/docs/understanding-service-
accounts#using_service_accounts_with_compute_engine
NEW QUESTION # 90
A large financial institution is moving its Big Data analytics to Google Cloud Platform. They want to have maximum control over the encryption process of data stored at rest in BigQuery.
What technique should the institution use?
- A. Use Cloud Storage as a federated Data Source.
- B. Customer-managed encryption keys (CMEK).
- C. Customer-supplied encryption keys (CSEK).
- D. Use a Cloud Hardware Security Module (Cloud HSM).
Answer: B
Explanation:
Explanation/Reference: https://cloud.google.com/bigquery/docs/encryption-at-rest
NEW QUESTION # 91
You are a member of the security team at an organization. Your team has a single GCP project with credit card payment processing systems alongside web applications and data processing systems. You want to reduce the scope of systems subject to PCI audit standards.
What should you do?
- A. Move the cardholder data environment into a separate GCP project.
- B. Use only applications certified compliant with PA-DSS.
- C. Use multi-factor authentication for admin access to the web application.
- D. Use VPN for all connections between your office and cloud environments.
Answer: D
Explanation:
Reference:
https://cloud.google.com/solutions/pci-dss-compliance-in-gcp
NEW QUESTION # 92
Your company is storing files on Cloud Storage. To comply with local regulations, you want to ensure that uploaded files cannot be deleted within the first 5 years. It should not be possible to lower the retention period after it has been set. What should you do?
- A. Create an object lifecycle rule using the Age condition and the Delete action. Set the Age condition to 5 years.
- B. Use Cloud IAM to ensure that nobody has an IAM role that has the permissions to delete files from Cloud Storage.
- C. Apply a retention period of 5 years to the bucket, and lock the bucket.
- D. Enable Temporary hold and apply a retention period of 5 years to the bucket.
Answer: C
Explanation:
A is correct because Bucket Lock allows you to configure a data retention policy for a Cloud Storage bucket that governs how long objects in the bucket must be retained. The feature also allows you to lock the data retention policy, permanently preventing the policy from being reduced or removed.
B is not correct because object holds can be easily released by operators/admins.
C is not correct because an admin can grant themselves or someone else enough rights to tamper with the files in Cloud Storage.
D is not correct because Age condition and a Delete action does not prevent objects from being manually deleted before the Age condition is met.
https://cloud.google.com/storage/docs/bucket-lock
NEW QUESTION # 93
An organization is starting to move its infrastructure from its on-premises environment to Google Cloud Platform (GCP). The first step the organization wants to take is to migrate its ongoing data backup and disaster recovery solutions to GCP. The organization's on-premises production environment is going to be the next phase for migration to GCP. Stable networking connectivity between the on-premises environment and GCP is also being implemented.
Which GCP solution should the organization use?
- A. Cloud Datastore using regularly scheduled batch upload jobs via Cloud VPN
- B. Cloud Storage using a scheduled task and gsutil via Cloud Interconnect
- C. BigQuery using a data pipeline job with continuous updates via Cloud VPN
- D. Compute Engines Virtual Machines using Persistent Disk via Cloud Interconnect
Answer: B
Explanation:
Reference:
https://cloud.google.com/solutions/migration-to-google-cloud-building-your-foundation
NEW QUESTION # 94
You are exporting application logs to Cloud Storage. You encounter an error message that the log sinks don't support uniform bucket-level access policies. How should you resolve this error?
- A. Add the roles/logging.logWriter Identity and Access Management (IAM) role to the bucket for the log sink identity.
- B. Add the roles/logging.bucketWriter Identity and Access Management (IAM) role to the bucket for the log sink identity.
- C. Update your sink with the correct bucket destination.
- D. Change the access control model for the bucket
Answer: C
NEW QUESTION # 95
You are on your company's development team. You noticed that your web application hosted in staging on GKE dynamically includes user data in web pages without first properly validating the inputted dat a. This could allow an attacker to execute gibberish commands and display arbitrary content in a victim user's browser in a production environment.
How should you prevent and fix this vulnerability?
- A. Use Cloud IAP based on IP address or end-user device attributes to prevent and fix the vulnerability.
- B. Set up an HTTPS load balancer, and then use Cloud Armor for the production environment to prevent the potential XSS attack.
- C. Use Web Security Scanner in staging to simulate an XSS injection attack, and then use a templating system that supports contextual auto-escaping.
- D. Use Web Security Scanner to validate the usage of an outdated library in the code, and then use a secured version of the included library.
Answer: C
Explanation:
Reference:
https://cloud.google.com/security-scanner/docs/remediate-findings
NEW QUESTION # 96
You need to follow Google-recommended practices to leverage envelope encryption and encrypt data at the application layer.
What should you do?
- A. Generate a data encryption key (DEK) locally to encrypt the data, and generate a new key encryption key (KEK) in Cloud KMS to encrypt the DEK. Store both the encrypted data and the KEK.
- B. Generate a data encryption key (DEK) locally to encrypt the data, and generate a new key encryption key (KEK) in Cloud KMS to encrypt the DEK. Store both the encrypted data and the encrypted DEK.
- C. Generate a new data encryption key (DEK) in Cloud KMS to encrypt the data, and generate a key encryption key (KEK) locally to encrypt the key. Store both the encrypted data and the KEK.
- D. Generate a new data encryption key (DEK) in Cloud KMS to encrypt the data, and generate a key encryption key (KEK) locally to encrypt the key. Store both the encrypted data and the encrypted DEK.
Answer: B
Explanation:
Explanation/Reference: https://cloud.google.com/kms/docs/envelope-encryption
NEW QUESTION # 97
You are exporting application logs to Cloud Storage. You encounter an error message that the log sinks don't support uniform bucket-level access policies. How should you resolve this error?
- A. Add the roles/logging.logWriter Identity and Access Management (IAM) role to the bucket for the log sink identity.
- B. Update your sink with the correct bucket destination.
- C. Add the roles/logging.bucketWriter Identity and Access Management (IAM) role to the bucket for the log sink identity.
- D. Change the access control model for the bucket
Answer: D
Explanation:
Explanation
https://cloud.google.com/logging/docs/export/troubleshoot#errors_exporting_to_cloud_storage
https://cloud.google.com/logging/docs/export/troubleshoot
Unable to grant correct permissions to the destination: Even if the sink was successfully created with the correct service account permissions, this error message displays if the access control model for the Cloud Storage bucket was set to uniform access when the bucket was created. For existing Cloud Storage buckets, you can change the access control model for the first 90 days after bucket creation by using the Permissions tab. For new buckets, select the Fine-grained access control model during bucket creation. For details, see Creating Cloud Storage buckets.
NEW QUESTION # 98
......
Use Real Google Achieve the Professional-Cloud-Security-Engineer Dumps - 100% Exam Passing Guarantee: https://www.pass4suresvce.com/Professional-Cloud-Security-Engineer-pass4sure-vce-dumps.html
Free Test Engine Verified By Google Cloud Certified Certified Experts: https://drive.google.com/open?id=1z_7C_CDjCZxpr4RIV_VD78086S93zkh9