Get Ready to Pass the Professional-Cloud-Security-Engineer exam Right Now Using Our Google Cloud Certified Exam Package [Q64-Q87]

Share

Get Ready to Pass the Professional-Cloud-Security-Engineer exam Right Now Using Our Google Cloud Certified Exam Package

Enhance Your Career With Available Preparation Guide for Professional-Cloud-Security-Engineer Exam

NEW QUESTION 64
You have been tasked with configuring Security Command Center for your organization's Google Cloud environment. Your security team needs to receive alerts of potential crypto mining in the organization's compute environment and alerts for common Google Cloud misconfigurations that impact security. Which Security Command Center features should you use to configure these alerts? (Choose two.)

  • A. Container Threat Detection
  • B. Google Cloud Armor
  • C. Event Threat Detection
  • D. Cloud Data Loss Prevention
  • E. Security Health Analytics

Answer: B,C

 

NEW QUESTION 65
Applications often require access to "secrets" - small pieces of sensitive data at build or run time. The administrator managing these secrets on GCP wants to keep a track of "who did what, where, and when?" within their GCP projects.
Which two log streams would provide the information that the administrator is looking for? (Choose two.)

  • A. VPC Flow logs
  • B. Agent logs
  • C. System Event logs
  • D. Data Access logs
  • E. Admin Activity logs

Answer: D,E

 

NEW QUESTION 66
A large financial institution is moving its Big Data analytics to Google Cloud Platform. They want to have maximum control over the encryption process of data stored at rest in BigQuery.
What technique should the institution use?

  • A. Use a Cloud Hardware Security Module (Cloud HSM).
  • B. Customer-managed encryption keys (CMEK).
  • C. Use Cloud Storage as a federated Data Source.
  • D. Customer-supplied encryption keys (CSEK).

Answer: B

 

NEW QUESTION 67
Last week, a company deployed a new App Engine application that writes logs to BigQuery. No other workloads are running in the project. You need to validate that all data written to BigQuery was done using the App Engine Default Service Account.
What should you do?

  • A. 1. Use StackDriver Logging and filter on BigQuery Insert Jobs.
    2. Click on the email address in line with the App Engine Default Service Account in the authentication field.
    3. Click Show Matching Entries.
    4. Make sure the resulting list is empty.
  • B. 1. In BigQuery, select the related dataset.
    2. Make sure the App Engine Default Service Account is the only account that can write to the dataset.
  • C. 1. Use StackDriver Logging and filter on BigQuery Insert Jobs.
    2. Click on the email address in line with the App Engine Default Service Account in the authentication field.
    3. Click Hide Matching Entries.
    4. Make sure the resulting list is empty.
  • D. 1. Go to the IAM section on the project.
    2. Validate that the App Engine Default Service Account is the only account that has a role that can write to BigQuery.
    Section: (none)
    Explanation

Answer: B

 

NEW QUESTION 68
While migrating your organization's infrastructure to GCP, a large number of users will need to access GCP Console. The Identity Management team already has a well-established way to manage your users and want to keep using your existing Active Directory or LDAP server along with the existing SSO password.
What should you do?

  • A. Users sign in using OpenID (OIDC) compatible IdP, receive an authentication token, then use that token to log in to the GCP Console.
  • B. Manually synchronize the data in Google domain with your existing Active Directory or LDAP server.
  • C. Users sign in directly to the GCP Console using the credentials from your on-premises Kerberos compliant identity provider.
  • D. Use Google Cloud Directory Sync to synchronize the data in Google domain with your existing Active Directory or LDAP server.

Answer: D

Explanation:
Explanation
https://cloud.google.com/architecture/identity/federating-gcp-with-active-directory-configuring-single-sign-on

 

NEW QUESTION 69
Your team needs to configure their Google Cloud Platform (GCP) environment so they can centralize the control over networking resources like firewall rules, subnets, and routes. They also have an on-premises environment where resources need access back to the GCP resources through a private VPN connection. The networking resources will need to be controlled by the network security team.
Which type of networking design should your team use to meet these requirements?

  • A. Shared VPC Network with a host project and service projects
  • B. Cloud VPN Gateway between all engineering projects using a hub and spoke model
  • C. Grant Compute Admin role to the networking team for each engineering project
  • D. VPC peering between all engineering projects using a hub and spoke model

Answer: A

Explanation:
https://cloud.google.com/docs/enterprise/best-practices-for-enterprise- organizations#centralize_network_control

 

NEW QUESTION 70
You want to evaluate GCP for PCI compliance. You need to identify Google's inherent controls.
Which document should you review to find the information?

  • A. Google Cloud Platform: Customer Responsibility Matrix
  • B. PCI SSC Cloud Computing Guidelines
  • C. Product documentation for Compute Engine
  • D. PCI DSS Requirements and Security Assessment Procedures

Answer: A

Explanation:
https://cloud.google.com/files/PCI_DSS_Shared_Responsibility_GCP_v32.pdf

 

NEW QUESTION 71
An organization adopts Google Cloud Platform (GCP) for application hosting services and needs guidance on setting up password requirements for their Cloud Identity account. The organization has a password policy requirement that corporate employee passwords must have a minimum number of characters.
Which Cloud Identity password guidelines can the organization use to inform their new requirements?

  • A. Set the minimum length for passwords to be 8 characters.
  • B. Set the minimum length for passwords to be 6 characters.
  • C. Set the minimum length for passwords to be 10 characters.
  • D. Set the minimum length for passwords to be 12 characters.

Answer: A

Explanation:
Default password length is 8 characters. https://support.google.com/cloudidentity/answer/33319?hl=en

 

NEW QUESTION 72
You want to protect the default VPC network from all inbound and outbound internet traffic. What action should you take?

  • A. Create instances without external IP addresses only.
  • B. Create a Deny All outbound internet firewall rule.
  • C. Create a new subnet in the VPC network with private Google access enabled.
  • D. Create a Deny All inbound internet firewall rule.

Answer: B

Explanation:
A is not correct because a Deny All inbound firewall is already part of the standard configuration and does not need to be added.
B is correct because all inbound traffic is already blocked, but all egress traffic is allowed by default. To prevent any outbound traffic an extra rule needs to be added.
C is not correct because private Google allows calls to Google managed APIs from private IP addresses, but it does neither prevent you from providing external IPs or any other outgoing traffic from your instances.
D is not correct because as outbound traffic can still be coming from instances with private IPs if Cloud NAT is used.
https://cloud.google.com/nat/docs/overview
https://cloud.google.com/vpc/docs/private-access-options
https://cloud.google.com/vpc/docs/using-firewalls

 

NEW QUESTION 73
A customer needs to prevent attackers from hijacking their domain/IP and redirecting users to a malicious site through a man-in-the-middle attack.
Which solution should this customer use?

  • A. Cloud Identity-Aware Proxy
  • B. DNS Security Extensions
  • C. Cloud Armor
  • D. VPC Flow Logs

Answer: B

Explanation:
https://cloud.google.com/blog/products/gcp/dnssec-now-available-in-cloud-dns

 

NEW QUESTION 74
You need to set up a Cloud interconnect connection between your company's on-premises data center and VPC host network. You want to make sure that on-premises applications can only access Google APIs over the Cloud Interconnect and not through the public internet. You are required to only use APIs that are supported by VPC Service Controls to mitigate against exfiltration risk to non-supported APIs. How should you configure the network?

  • A. Set up a Private Service Connect endpoint IP address with the API bundle of "all-apis", which is advertised as a route over the Cloud interconnect connection.
  • B. Enable Private Google Access on the regional subnets and global dynamic routing mode.
  • C. Use private.googleapis.com to access Google APIs using a set of IP addresses only routable from within Google Cloud, which are advertised as routes over the connection.
  • D. Use restricted googleapis.com to access Google APIs using a set of IP addresses only routable from within Google Cloud, which are advertised as routes over the Cloud Interconnect connection.

Answer: A

 

NEW QUESTION 75
A company has been running their application on Compute Engine. A bug in the application allowed a malicious user to repeatedly execute a script that results in the Compute Engine instance crashing. Although the bug has been fixed, you want to get notified in case this hack re-occurs.
What should you do?

  • A. Log every execution of the script to Stackdriver Logging. Create a User-defined metric in Stackdriver Logging on the logs, and create a Stackdriver Dashboard displaying the metric.
  • B. Log every execution of the script to Stackdriver Logging. Configure BigQuery as a log sink, and create a BigQuery scheduled query to count the number of executions in a specific timeframe.
  • C. Create an Alerting Policy in Stackdriver using a Process Health condition, checking that the number of executions of the script remains below the desired threshold. Enable notifications.
  • D. Create an Alerting Policy in Stackdriver using the CPU usage metric. Set the threshold to 80% to be notified when the CPU usage goes above this 80%.

Answer: A

Explanation:
Reference:
https://cloud.google.com/logging/docs/logs-based-metrics/

 

NEW QUESTION 76
A company's application is deployed with a user-managed Service Account key. You want to use Google- recommended practices to rotate the key.
What should you do?

  • A. Create a new key, and use the new key in the application. Store the old key on the system as a backup key.
  • B. Open Cloud Shell and run gcloud iam service-accounts enable-auto-rotate --iam- account=IAM_ACCOUNT.
  • C. Create a new key, and use the new key in the application. Delete the old key from the Service Account.
  • D. Open Cloud Shell and run gcloud iam service-accounts keys rotate --iam- account=IAM_ACCOUNT
    --key=NEW_KEY.

Answer: C

Explanation:
Explanation
You can rotate a key by creating a new key, updating applications to use the new key, and deleting the old key.
Use the serviceAccount.keys.create() method and serviceAccount.keys.delete() method together to automate the rotation.

 

NEW QUESTION 77
As adoption of the Cloud Data Loss Prevention (DLP) API grows within the company, you need to optimize usage to reduce cost. DLP target data is stored in Cloud Storage and BigQuery. The location and region are identified as a suffix in the resource name.
Which cost reduction options should you recommend?

  • A. Use rowsLimit and bytesLimitPerFile to sample data and use CloudStorageRegexFileSet to limit scans.
  • B. Set appropriate rowsLimit value on BigQuery data hosted outside the US and set appropriate bytesLimitPerFile value on multiregional Cloud Storage buckets.
  • C. Use FindingLimits and TimespanContfig to sample data and minimize transformation units.
  • D. Set appropriate rowsLimit value on BigQuery data hosted outside the US, and minimize transformation units on multiregional Cloud Storage buckets.

Answer: A

Explanation:
Explanation
https://cloud.google.com/dlp/docs/inspecting-storage#sampling
https://cloud.google.com/dlp/docs/best-practices-costs#limit_scans_of_files_in_to_only_relevant_files

 

NEW QUESTION 78
You have an application where the frontend is deployed on a managed instance group in subnet A and the data layer is stored on a mysql Compute Engine virtual machine (VM) in subnet B on the same VPC. Subnet A and Subnet B hold several other Compute Engine VMs. You only want to allow thee application frontend to access the data in the application's mysql instance on port 3306.
What should you do?

  • A. Configure a network tag "fe-tag" to be applied to all instances in subnet A and a network tag "data-tag" to be applied to all instances in subnet B. Then configure an egress firewall rule that allows communication from Compute Engine VMs tagged with data-tag to destination Compute Engine VMs tagged fe-tag.
  • B. Configure an ingress firewall rule that allows communication from the frontend's unique service account to the unique service account of the mysql Compute Engine VM on port 3306.
  • C. Configure an ingress firewall rule that allows communication from the src IP range of subnet A to the tag "data-tag" that is applied to the mysql Compute Engine VM on port 3306.
  • D. Configure a network tag "fe-tag" to be applied to all instances in subnet A and a network tag "data-tag" to be applied to all instances in subnet B. Then configure an ingress firewall rule that allows communication from Compute Engine VMs tagged with fe-tag to destination Compute Engine VMs tagged with data-tag.

Answer: B

Explanation:
Explanation
https://cloud.google.com/sql/docs/mysql/sql-proxy#using-a-service-account

 

NEW QUESTION 79
Which Google Cloud service should you use to enforce access control policies for applications and resources?

  • A. Cloud NAT
  • B. Shielded VMs
  • C. Identity-Aware Proxy
  • D. Google Cloud Armor

Answer: C

 

NEW QUESTION 80
A customer deploys an application to App Engine and needs to check for Open Web Application Security Project (OWASP) vulnerabilities.
Which service should be used to accomplish this?

  • A. Cloud Security Scanner
  • B. Cloud Armor
  • C. Forseti Security
  • D. Google Cloud Audit Logs

Answer: A

Explanation:
https://cloud.google.com/security-scanner/

 

NEW QUESTION 81
A customer has an analytics workload running on Compute Engine that should have limited internet access.
Your team created an egress firewall rule to deny (priority 1000) all traffic to the internet.
The Compute Engine instances now need to reach out to the public repository to get security updates.
What should your team do?

  • A. Create an egress firewall rule to allow traffic to the CIDR range of the repository with a priority less than
    1000.
  • B. Create an egress firewall rule to allow traffic to the hostname of the repository with a priority less than 1000.
  • C. Create an egress firewall rule to allow traffic to the hostname of the repository with a priority greater than
    1000.
  • D. Create an egress firewall rule to allow traffic to the CIDR range of the repository with a priority greater than
    1000.

Answer: C

 

NEW QUESTION 82
Your team needs to obtain a unified log view of all development cloud projects in your SIEM. The development projects are under the NONPROD organization folder with the test and pre-production projects. The development projects share the ABC-BILLING billing account with the rest of the organization.
Which logging export strategy should you use to meet the requirements?

  • A. 1. Export logs to a Cloud Pub/Sub topic with folders/NONPROD parent and includeChildren property set to True in a dedicated SIEM project.
    2. Subscribe SIEM to the topic.
  • B. 1. Export logs in each dev project to a Cloud Pub/Sub topic in a dedicated SIEM project.
    2. Subscribe SIEM to the topic.
  • C. 1. Create a Cloud Storage sink with a publicly shared Cloud Storage bucket in each project.
    2. Process Cloud Storage objects in SIEM.
  • D. 1. Create a Cloud Storage sink with billingAccounts/ABC-BILLING parent and includeChildren property set to False in a dedicated SIEM project.
    2. Process Cloud Storage objects in SIEM.

Answer: D

 

NEW QUESTION 83
You want to evaluate GCP for PCI compliance. You need to identify Google's inherent controls.
Which document should you review to find the information?

  • A. Product documentation for Compute Engine
  • B. PCI DSS Requirements and Security Assessment Procedures
  • C. PCI SSC Cloud Computing Guidelines
  • D. Google Cloud Platform: Customer Responsibility Matrix

Answer: C

 

NEW QUESTION 84
You are in charge of creating a new Google Cloud organization for your company. Which two actions should you take when creating the super administrator accounts? (Choose two.)

  • A. Provide non-privileged identities to the super admin users for their day-to-day activities.
  • B. Use a physical token to secure the super admin credentials with multi-factor authentication (MFA).
  • C. Disable any Identity and Access Management (1AM) roles for super admin at the organization level in the Google Cloud Console.
  • D. Use a private connection to create the super admin accounts to avoid sending your credentials over the Internet.
  • E. Create an access level in the Google Admin console to prevent super admin from logging in to Google Cloud.

Answer: B,E

 

NEW QUESTION 85
A company is backing up application logs to a Cloud Storage bucket shared with both analysts and the administrator. Analysts should only have access to logs that do not contain any personally identifiable information (PII). Log files containing PII should be stored in another bucket that is only accessible by the administrator.
What should you do?

  • A. On the bucket shared with both the analysts and the administrator, configure a Cloud Storage Trigger that is only triggered when PII data is uploaded. Use Cloud Functions to capture the trigger and delete such files.
  • B. On the bucket shared with both the analysts and the administrator, configure Object Lifecycle Management to delete objects that contain any PII.
  • C. Use Cloud Pub/Sub and Cloud Functions to trigger a Data Loss Prevention scan every time a file is uploaded to the shared bucket. If the scan detects PII, have the function move into a Cloud Storage bucket only accessible by the administrator.
  • D. Upload the logs to both the shared bucket and the bucket only accessible by the administrator. Create a job trigger using the Cloud Data Loss Prevention API. Configure the trigger to delete any files from the shared bucket that contain PII.

Answer: C

Explanation:
Explanation
https://codelabs.developers.google.com/codelabs/cloud-storage-dlp-functions#0
https://www.youtube.com/watch?v=0TmO1f-Ox40

 

NEW QUESTION 86
Your organization has implemented synchronization and SAML federation between Cloud Identity and Microsoft Active Directory. You want to reduce the risk of Google Cloud user accounts being compromised.
What should you do?

  • A. Create a Cloud Identity password policy with strong password settings, and configure 2-Step Verification with verification codes via text or phone call in the Google Admin console.
  • B. Create an Active Directory domain password policy with strong password settings, and configure post-SSO (single sign-on) 2-Step Verification with security keys in the Google Admin console.
  • C. Create a Cloud Identity password policy with strong password settings, and configure 2-Step Verification with security keys in the Google Admin console.
  • D. Create an Active Directory domain password policy with strong password settings, and configure post-SSO (single sign-on) 2-Step Verification with verification codes via text or phone call in the Google Admin console.

Answer: B

 

NEW QUESTION 87
......

Get Special Discount Offer of Professional-Cloud-Security-Engineer Certification Exam Sample Questions and Answers: https://www.actualvce.com/Google/Professional-Cloud-Security-Engineer-valid-vce-dumps.html

New Professional-Cloud-Security-Engineer Dumps For Preparing Google Cloud Certified Certified Google Exam Well: https://drive.google.com/open?id=1NAJPgRZlVSpdp5rk_sAazwZK8dm9YH8I