
Google Professional-Cloud-Security-Engineer Exam Dumps [2023] Practice Valid Exam Dumps Question
Professional-Cloud-Security-Engineer Dumps - Grab Out For [NEW-2023] Google Exam
Google Professional-Cloud-Security-Engineer exam is designed for individuals with a strong background in cloud security, including security engineers, security architects, and security analysts. Google Cloud Certified - Professional Cloud Security Engineer Exam certification is ideal for those who are looking to advance their careers in cloud security and demonstrate their expertise in Google Cloud Platform. It is also valuable for businesses and organizations that need to secure their cloud infrastructure and data and want to hire professionals with proven expertise in GCP security.
Google Professional-Cloud-Security-Engineer certification exam is designed for individuals who want to demonstrate their expertise in securing applications and infrastructure on the Google Cloud Platform. Professional-Cloud-Security-Engineer exam tests candidates’ knowledge and skills in the areas of cloud security design, implementation, and monitoring. It is a challenging, hands-on exam that requires individuals to demonstrate their ability to apply industry best practices to real-world scenarios.
The Google Professional-Cloud-Security-Engineer exam covers a wide range of topics related to cloud security, including network security, data protection, identity and access management, compliance and regulation, and incident response. The primary goal of the exam is to ensure that certified professionals possess a deep understanding of the security challenges and opportunities that come with cloud computing.
NEW QUESTION # 32
Your organization has on-premises hosts that need to access Google Cloud APIs You must enforce private connectivity between these hosts minimize costs and optimize for operational efficiency What should you do?
- A. Route all on-premises traffic to Google Cloud through an IPsec VPN tunnel to a VPC with Private Google Access enabled.
- B. Enforce a security policy that mandates all applications to encrypt data with a Cloud Key Management. Service (KMS) key before you send it over the network.
- C. Route all on-premises traffic to Google Cloud through a dedicated or Partner interconnect to a VPC with Private Google Access enabled.
- D. Set up VPC peering between the hosts on-premises and the VPC through the internet.
Answer: C
NEW QUESTION # 33
A manager wants to start retaining security event logs for 2 years while minimizing costs. You write a filter to select the appropriate log entries.
Where should you export the logs?
- A. BigQuery datasets
- B. Cloud Pub/Sub topics
- C. Cloud Storage buckets
- D. StackDriver logging
Answer: D
Explanation:
https://cloud.google.com/logging/docs/exclusions
NEW QUESTION # 34
A company allows every employee to use Google Cloud Platform. Each department has a Google Group, with all department members as group members. If a department member creates a new project, all members of that department should automatically have read-only access to all new project resources. Members of any other department should not have access to the project. You need to configure this behavior.
What should you do to meet these requirements?
- A. Create a Project per department under the Organization. For each department's Project, assign the Project Browser role to the Google Group related to that department.
- B. Create a Folder per department under the Organization. For each department's Folder, assign the Project Browser role to the Google Group related to that department.
- C. Create a Folder per department under the Organization. For each department's Folder, assign the Project Viewer role to the Google Group related to that department.
- D. Create a Project per department under the Organization. For each department's Project, assign the Project Viewer role to the Google Group related to that department.
Answer: C
Explanation:
https://cloud.google.com/iam/docs/understanding-roles#project-roles
NEW QUESTION # 35
You work for a large organization where each business unit has thousands of users. You need to delegate management of access control permissions to each business unit. You have the following requirements:
Each business unit manages access controls for their own projects.
Each business unit manages access control permissions at scale.
Business units cannot access other business units' projects.
Users lose their access if they move to a different business unit or leave the company.
Users and access control permissions are managed by the on-premises directory service.
What should you do? (Choose two.)
- A. Use Google Cloud Directory Sync to synchronize users and group memberships in Cloud Identity.
- B. Organize projects in folders, and assign permissions to Google groups at the folder level.
- C. Create a project naming convention, and use Google's IAM Conditions to manage access based on the prefix of project names.
- D. Use VPC Service Controls to create perimeters around each business unit's project.
- E. Group business units based on Organization Units (OUs) and manage permissions based on OUs.
Answer: A,C
NEW QUESTION # 36
Your Security team believes that a former employee of your company gained unauthorized access to Google Cloud resources some time in the past 2 months by using a service account key. You need to confirm the unauthorized access and determine the user activity. What should you do?
- A. Use Security Health Analytics to determine user activity.
- B. Use the Logs Explorer to search for user activity.
- C. Use the Cloud Data Loss Prevention API to query logs in Cloud Storage.
- D. Use the Cloud Monitoring console to filter audit logs by user.
Answer: D
NEW QUESTION # 37
A business unit at a multinational corporation signs up for GCP and starts moving workloads into GCP. The business unit creates a Cloud Identity domain with an organizational resource that has hundreds of projects.
Your team becomes aware of this and wants to take over managing permissions and auditing the domain resources.
Which type of access should your team grant to meet this requirement?
- A. Organization Policy Administrator
- B. Organization Administrator
- C. Organization Role Administrator
- D. Security Reviewer
Answer: C
Explanation:
Here are the permissions available to organizationRoleAdmin
iam.roles.create
iam.roles.delete
iam.roles.undelete
iam.roles.get
iam.roles.list
iam.roles.update
resourcemanager.projects.get
resourcemanager.projects.getIamPolicy
resourcemanager.projects.list
resourcemanager.organizations.get
resourcemanager.organizations.getIamPolicy
There are sufficient as per least privilege policy. You can do user management as well as auditing.
https://cloud.google.com/iam/docs/understanding-custom-roles
NEW QUESTION # 38
After completing a security vulnerability assessment, you learned that cloud administrators leave Google Cloud CLI sessions open for days. You need to reduce the risk of attackers who might exploit these open sessions by setting these sessions to the minimum duration.
What should you do?
- A. Set the session duration for the Google session control to one hour.
- B. Set the organization policy constraint
constraints/iam.allowServiceAccountCredentialLifetimeExtension to one hour. - C. Set the reauthentication frequency (or the Google Cloud Session Control to one hour.
- D. Set the organization policy constraint constraints/iam. serviceAccountKeyExpiryHours to one hour and inheritFromParent to false.
Answer: C
NEW QUESTION # 39
You need to connect your organization's on-premises network with an existing Google Cloud environment that includes one Shared VPC with two subnets named Production and Non-Production. You are required to:
Use a private transport link.
Configure access to Google Cloud APIs through private API endpoints originating from on-premises environments.
Ensure that Google Cloud APIs are only consumed via VPC Service Controls.
What should you do?
- A. 1. Set up a Cloud VPN link between the on-premises environment and Google Cloud.
2. Configure private access using the restricted googleapis.com domains in on-premises DNS configurations. - B. 1. Set up a Partner Interconnect link between the on-premises environment and Google Cloud.
2. Configure private access using the private.googleapis.com domains in on-premises DNS configurations. - C. 1. Set up a Dedicated Interconnect link between the on-premises environment and Google Cloud.
2. Configure private access using the restricted.googleapis.com domains in on-premises DNS configurations. - D. 1. Set up a Direct Peering link between the on-premises environment and Google Cloud.
2. Configure private access for both VPC subnets.
Answer: C
Explanation:
Explanation
restricted.googleapis.com (199.36.153.4/30) only provides access to Cloud and Developer APIs that support VPC Service Controls. VPC Service Controls are enforced for these services
https://cloud.google.com/vpc/docs/configure-private-google-access-hybrid
NEW QUESTION # 40
You recently joined the networking team supporting your company's Google Cloud implementation. You are tasked with familiarizing yourself with the firewall rules configuration and providing recommendations based on your networking and Google Cloud experience. What product should you recommend to detect firewall rules that are overlapped by attributes from other firewall rules with higher or equal priority?
- A. VPC Flow Logs
- B. Firewall Insights
- C. Security Command Center
- D. Firewall Rules Logging
Answer: B
NEW QUESTION # 41
You need to implement an encryption-at-rest strategy that protects sensitive data and reduces key management complexity for non-sensitive data. Your solution has the following requirements:
* Schedule key rotation for sensitive data.
* Control which region the encryption keys for sensitive data are stored in.
* Minimize the latency to access encryption keys for both sensitive and non-sensitive data.
What should you do?
- A. Encrypt non-sensitive data with Google default encryption, and encrypt sensitive data with Cloud External Key Manager.
- B. Encrypt non-sensitive data and sensitive data with Cloud External Key Manager.
- C. Encrypt non-sensitive data with Google default encryption, and encrypt sensitive data with Cloud Key Management Service.
- D. Encrypt non-sensitive data and sensitive data with Cloud Key Management Service.
Answer: C
Explanation:
Explanation
Google uses a common cryptographic library, Tink, which incorporates our FIPS 140-2 Level 1 validated module, BoringCrypto, to implement encryption consistently across almost all Google Cloud products. To provideflexibility of controlling the key residency and rotation schedule, use google provided key for non-sensitive and encrypt sensitive data with Cloud Key Management Service
NEW QUESTION # 42
A customer wants to move their sensitive workloads to a Compute Engine-based cluster using Managed Instance Groups (MIGs). The jobs are bursty and must be completed quickly. They have a requirement to be able to manage and rotate the encryption keys.
Which boot disk encryption solution should you use on the cluster to meet this customer's requirements?
- A. Encryption by default
- B. Customer-supplied encryption keys (CSEK)
- C. Pre-encrypting files before transferring to Google Cloud Platform (GCP) for analysis
- D. Customer-managed encryption keys (CMEK) using Cloud Key Management Service (KMS)
Answer: D
Explanation:
Explanation
Reference https://cloud.google.com/kubernetes-engine/docs/how-to/dynamic-provisioning-cmek
NEW QUESTION # 43
A DevOps team will create a new container to run on Google Kubernetes Engine. As the application will be internet-facing, they want to minimize the attack surface of the container.
What should they do?
- A. Delete non-used versions from Container Registry.
- B. Build small containers using small base images.
- C. Use Cloud Build to build the container images.
- D. Use a Continuous Delivery tool to deploy the application.
Answer: D
NEW QUESTION # 44
Your organization recently activated the Security Command Center {SCO standard tier. There are a few Cloud Storage buckets that were accidentally made accessible to the public. You need to investigate the impact of the incident and remediate it.
What should you do?
- A. * 1 Change permissions to limit access for authorized users
* 2 Enforce a VPC Service Controls perimeter around all the production projects to immediately stop any unauthorized access
* 3 Review the administrator activity audit logs to report on any unauthorized access - B. * 1 Change the bucket permissions to limit access
* 2 Query the buckets usage logs to report on unauthorized access to the data
* 3 Enforce the organization policy storage.publicAccessPrevention to avoid regressions - C. * 1 Change bucket permissions to limit access
* 2 Query the data access audit logs for any unauthorized access to the buckets
* 3 After the misconfiguration is corrected mute the finding in the Security Command Center - D. * 1 Remove the Identity and Access Management (IAM) granting access to allusers from the buckets
* 2 Apply the organization policy storage. unifromBucketLevelAccess to prevent regressions
* 3 Query the data access logs to report on unauthorized access
Answer: C
Explanation:
■■
NEW QUESTION # 45
You are on your company's development team. You noticed that your web application hosted in staging on GKE dynamically includes user data in web pages without first properly validating the inputted data. This could allow an attacker to execute gibberish commands and display arbitrary content in a victim user's browser in a production environment.
How should you prevent and fix this vulnerability?
- A. Use Web Security Scanner in staging to simulate an XSS injection attack, and then use a templating system that supports contextual auto-escaping.
- B. Use Cloud IAP based on IP address or end-user device attributes to prevent and fix the vulnerability.
- C. Set up an HTTPS load balancer, and then use Cloud Armor for the production environment to prevent the potential XSS attack.
- D. Use Web Security Scanner to validate the usage of an outdated library in the code, and then use a secured version of the included library.
Answer: A
Explanation:
https://cloud.google.com/security-scanner/docs/remediate-findings
NEW QUESTION # 46
Your Google Cloud organization allows for administrative capabilities to be distributed to each team through provision of a Google Cloud project with Owner role (roles/ owner). The organization contains thousands of Google Cloud Projects Security Command Center Premium has surfaced multiple cpen_myscl_port findings. You are enforcing the guardrails and need to prevent these types of common misconfigurations.
What should you do?
- A. Create a firewall rule for each virtual private cloud (VPC) to deny traffic from 0 0 0 0/0 with priority 0.
- B. Create a hierarchical firewall policy configured at the organization to deny all connections from 0 0 0 0/0.
- C. Create a Google Cloud Armor security policy to deny traffic from 0 0 0 0/0.
- D. Create a hierarchical firewall policy configured at the organization to allow connections only from internal IP ranges
Answer: B
NEW QUESTION # 47
Your company requires the security and network engineering teams to identify all network anomalies within and across VPCs, internal traffic from VMs to VMs, traffic between end locations on the internet and VMs, and traffic between VMs to Google Cloud services in production. Which method should you use?
- A. Enable VPC Flow Logs on the subnet.
- B. Configure packet mirroring policies.
- C. Monitor and analyze Cloud Audit Logs.
- D. Define an organization policy constraint.
Answer: B
Explanation:
Explanation
https://cloud.google.com/vpc/docs/packet-mirroring#enterprise_security
Security and network engineering teams must ensure that they are catching all anomalies and threats that might indicate security breaches and intrusions. They mirror all traffic so that they can complete a comprehensive inspection of suspicious flows.
NEW QUESTION # 48
You are working with protected health information (PHI) for an electronic health record system. The privacy officer is concerned that sensitive data is stored in the analytics system. You are tasked with anonymizing the sensitive data in a way that is not reversible. Also, the anonymized data should not preserve the character set and length. Which Google Cloud solution should you use?
- A. Cloud Data Loss Prevention with deterministic encryption using AES-SIV
- B. Cloud Data Loss Prevention with cryptographic hashing
- C. Cloud Data Loss Prevention with Cloud Key Management Service wrapped cryptographic keys
- D. Cloud Data Loss Prevention with format-preserving encryption
Answer: C
NEW QUESTION # 49
A customer deployed an application on Compute Engine that takes advantage of the elastic nature of cloud computing.
How can you work with Infrastructure Operations Engineers to best ensure that Windows Compute Engine VMs are up to date with all the latest OS patches?
- A. Federate a Domain Controller into Compute Engine, and roll out weekly patches via Group Policy Object.
- B. Use Deployment Manager to provision updated VMs into new serving Instance Groups (IGs).
- C. Reboot all VMs during the weekly maintenance window and allow the StartUp Script to download the latest patches from the internet.
- D. Build new base images when patches are available, and use a CI/CD pipeline to rebuild VMs, deploying incrementally.
Answer: C
NEW QUESTION # 50
You have noticed an increased number of phishing attacks across your enterprise user accounts. You want to implement the Google 2-Step Verification (2SV) option that uses a cryptographic signature to authenticate a user and verify the URL of the login page. Which Google 2SV option should you use?
- A. Google Authenticator app
- B. Google prompt
- C. Cloud HSM keys
- D. Titan Security Keys
Answer: A
NEW QUESTION # 51
A manager wants to start retaining security event logs for 2 years while minimizing costs. You write a filter to select the appropriate log entries.
Where should you export the logs?
- A. BigQuery datasets
- B. Cloud Pub/Sub topics
- C. Cloud Storage buckets
- D. StackDriver logging
Answer: D
Explanation:
Reference:
https://cloud.google.com/logging/docs/exclusions
NEW QUESTION # 52
You are a Cloud Identity administrator for your organization. In your Google Cloud environment groups are used to manage user permissions. Each application team has a dedicated group Your team is responsible for creating these groups and the application teams can manage the team members on their own through the Google Cloud console. You must ensure that the application teams can only add users from within your organization to their groups.
What should you do?
- A. Set an Identity and Access Management (1AM) policy that includes a condition that restricts group membership to user principals that belong to your organization.
- B. Define an Identity and Access Management (IAM) deny policy that denies the assignment of principals that are outside your organization to the groups in scope.
- C. Export the Cloud Identity logs to BigQuery Configure an alert for external members added to groups Have the alert trigger a Cloud Function instance that removes the external members from the group.
- D. Change the configuration of the relevant groups in the Google Workspace Admin console to prevent external users from being added to the group.
Answer: A
NEW QUESTION # 53
......
Professional-Cloud-Security-Engineer Exam Dumps PDF Guaranteed Success with Accurate & Updated Questions: https://www.passreview.com/Professional-Cloud-Security-Engineer_exam-braindumps.html
Pass Professional-Cloud-Security-Engineer Exam - Real Test Engine PDF with 212 Questions: https://drive.google.com/open?id=1vFIibFkjKXNJ67fGUCmUwUtEQb5Yr018