Question 1
Multiple choice
You work for a large organization where each business unit has thousands of users. You need to delegate management of access control permissions to each business unit. You have the following requirements: 1. Each business unit manages access controls for their own projects. 2. Each business unit manages access control permissions at scale. 3. Business units cannot access other business units' projects. 4. Users lose their access if they move to a different business unit or leave the company. 5. Users and access control permissions are managed by the on-premises directory service. What should you do? (Choose two.)
-
A
Use VPC Service Controls to create perimeters around each business unit's project.
-
B
Organize projects in folders, and assign permissions to Google groups at the folder level.
-
C
Group business units based on Organization Units (OUs) and manage permissions based on OUs.
-
D
Create a project naming convention, and use Google's IAM Conditions to manage access based on the prefix of project names.
-
E
Use Google Cloud Directory Sync to synchronize users and group memberships in Cloud Identity.
Reveal answer details
Close answer details
Users are reporting an outage on your public-facing application that is hosted on Compute Engine. You suspect that a recent change to your firewall rules is responsible. You need to test whether your firewall rules are working properly. What should you do?
-
A
Enable Firewall Rules Logging on the latest rules that were changed. Use Logs Explorer to analyze whether the rules are working correctly.
-
B
Connect to a bastion host in your VPC. Use a network traffic analyzer to determine at which point your requests are being blocked.
-
C
In a pre-production environment, disable all firewall rules individually to determine which one is blocking user traffic.
-
D
Enable VPC Flow Logs in your VPC. Use Logs Explorer to analyze whether the rules are working correctly.
Reveal answer details
Close answer details
Correct answerA
Explanationhttps://cloud.google.com/vpc/docs/using-flow-logs https://cloud.google.com/vpc/docs/firewall-rules-logging
Your organization uses BigQuery to process highly sensitive, structured datasets. Following the "need to know" principle, you need to create the Identity and Access Management (IAM) design to meet the needs of these users: 1. Business user: must access curated reports. 2. Data engineer: must administrate the data lifecycle in the platform 3. Security operator: must review user activity on the data platform. What should you do?
-
A
Configure data access log for BigQuery services, and grant Project Viewer role to security operator.
-
B
Set row-based access control based on the "region" column, and filter the record from the United States for data engineers.
-
C
Create curated tables in a separate dataset and assign the role roles/bigquery.dataViewer.
-
D
Generate a CSV data file based on the business user's needs, and send the data to their email addresses.
Reveal answer details
Close answer details
Correct answerC
ExplanationThe most correct answer would be C. Create curated tables in a separate dataset and assign the role roles/bigquery.dataViewer. This option directly addresses the needs of the business user who must access curated reports. By creating curated tables in a separate dataset, you can control access to specific data. Assigning the roles/ bigquery.dataViewer role allows the business user to view the data in BigQuery. While option A is also a good practice for a security operator, it doesn't directly address the specific needs of the users mentioned in the question as effectively as option C does. Therefore, if you can only choose one answer, option C would be the most correct.
Your company's Google Cloud organization has about 200 projects and 1,500 virtual machines. There is no uniform strategy for logs and events management, which reduces visibility for your security operations team. You need to design a logs management solution that provides visibility and allows the security team to view the environment's configuration. What should you do?
-
A
1. Create a dedicated log sink for each project that is in scope. 2. Use a BigQuery dataset with time partitioning enabled as a destination of the log sinks. 3. Deploy alerts based on log metrics in every project. 4. Grant the role "Monitoring Viewer" to the security operations team in each project.
-
B
1. Create one log sink at the organization level that includes all the child resources. 2. Use as destination a Pub/Sub topic to ingest the logs into the security information and event. management (SIEM) on-premises, and ensure that the right team can access the SIEM. 3. Grant the Viewer role at organization level to the security operations team.
-
C
1. Enable network logs and data access logs for all resources in the "Production" folder. 2. Do not create log sinks to avoid unnecessary costs and latency. 3. Grant the roles "Logs Viewer" and "Browser" at project level to the security operations team.
-
D
1. Create one sink for the "Production" folder that includes child resources and one sink for the logs ingested at the organization level that excludes child resources. 2. As destination, use a log bucket with a minimum retention period of 90 days in a project that can be accessed by the security team. 3. Grant the security operations team the role of Security Reviewer at organization level.
Reveal answer details
Close answer details
Correct answerB
Explanation1. Create one log sink at the organization level that includes all the child resources. 2. Use as destination a Pub/Sub topic to ingest the logs into the security information and event management (SIEM) on-premises, and ensure that the right team can access the SIEM.
A large e-retailer is moving to Google Cloud Platform with its ecommerce website. The company wants to ensure payment information is encrypted between the customer's browser and GCP when the customers checkout online. What should they do?
-
A
Configure an SSL Certificate on an L7 Load Balancer and require encryption.
-
B
Configure an SSL Certificate on a Network TCP Load Balancer and require encryption.
-
C
Configure the firewall to allow inbound traffic on port 443, and block all other inbound traffic.
-
D
Configure the firewall to allow outbound traffic on port 443, and block all other outbound traffic.
Reveal answer details
Close answer details
Correct answerA
Explanationhttps://cloud.google.com/load-balancing/docs/load-balancing-overview#external_versus_internal_load_balancing
You work for a large organization that is using Cloud Identity as the identity provider (IdP) on Google Cloud. Your InfoSec team has mandated the enforcement of a strong password with a length between 12 and 16 characters for all users. After configuring this requirement, users are still able to access the Google Cloud console with passwords that are less than 12 characters. You need to fix this problem within the Admin console. What should you do?
-
A
Review each user's password configuration and reset existing passwords.
-
B
Review the organization password management setting and select Enforce password policy at the next sign-in.
-
C
Review each user's password configuration and select Enforce strong password.
-
D
Review the organization password management setting and select Enforce strong password.
Reveal answer details
Close answer details
Your company requires the security and network engineering teams to identify all network anomalies and be able to capture payloads within VPCs. Which method should you use?
-
A
Define an organization policy constraint.
-
B
Configure packet mirroring policies.
-
C
Enable VPC Flow Logs on the subnet.
-
D
Monitor and analyze Cloud Audit Logs.
Reveal answer details
Close answer details
Correct answerB
Explanationhttps://cloud.google.com/vpc/docs/packet-mirroring Packet Mirroring clones the traffic of specified instances in your Virtual Private Cloud (VPC) network and forwards it for examination. Packet Mirroring captures all traffic and packet data, including payloads and headers.
As part of your organization's zero trust strategy, you use Identity-Aware Proxy (IAP) to protect multiple applications. You need to ingest logs into a Security Information and Event Management (SIEM) system so that you are alerted to possible intrusions. Which logs should you analyze?
-
A
-
B
-
C
Cloud Identity user log events
-
D
Admin Activity audit logs
Reveal answer details
Close answer details
Correct answerA
ExplanationThe data_access log name only appears if there was traffic to your resource after you enabled Cloud Audit Logs for IAP. Click to expand the date and time of the access you want to review. Authorized access has a blue i icon. Unauthorized access has an orange !! icon https://cloud.google.com/iap/docs/audit-log-howto
You are a member of your company's security team. You have been asked to reduce your Linux bastion host external attack surface by removing all public IP addresses. Site Reliability Engineers (SREs) require access to the bastion host from public locations so they can access the internal VPC while off-site. How should you enable this access?
-
A
Implement Cloud VPN for the region where the bastion host lives.
-
B
Implement OS Login with 2-step verification for the bastion host.
-
C
Implement Identity-Aware Proxy TCP forwarding for the bastion host.
-
D
Implement Google Cloud Armor in front of the bastion host.
Reveal answer details
Close answer details
Correct answerC
ExplanationReferences: https://cloud.google.com/architecture/building-internet-connectivity-for-private-vms https://cloud.google.com/architecture/building-internet-connectivity-for-private-vms#configuring_iap_tunnels_for_interacting_with_instances
Question 10
Single choice
You work for an ecommerce company that stores sensitive customer data across multiple Google Cloud regions. The development team has built a new 3-tier application to process orders and must integrate the application into the production environment. You must design the network architecture to ensure strong security boundaries and isolation for the new application, facilitate secure remote maintenance by authorized third-party vendors, and follow the principle of least privilege. What should you do?
-
A
Create separate VPC networks for each tier. Use VPC peering between application tiers and other required VPCs. Provide vendors with SSH keys and root access only to the instances within the VPC for maintenance purposes.
-
B
Create a single VPC network and create different subnets for each tier. Create a new Google project specifically for the third-party vendors and grant the network admin role to the vendors. Deploy a VPN appliance and rely on the vendors' configurations to secure third-party access.
-
C
Create separate VPC networks for each tier. Use VPC peering between application tiers and other required VPCs. Enable Identity-Aware Proxy (IAP) for remote access to management resources, limiting access to authorized vendors.
-
D
Create a single VPC network and create different subnets for each tier. Create a new Google project specifically for the third-party vendors. Grant the vendors ownership of that project and the ability to modify the Shared VPC configuration.
Reveal answer details
Close answer details
Question 11
Single choice
You are creating an internal App Engine application that needs to access a user's Google Drive on the user's behalf. Your company does not want to rely on the current user's credentials. It also wants to follow Google-recommended practices. What should you do?
-
A
Create a new Service account, and give all application users the role of Service Account User.
-
B
Create a new Service account, and add all application users to a Google Group. Give this group the role of Service Account User.
-
C
Use a dedicated G Suite Admin account, and authenticate the application's operations with these G Suite credentials.
-
D
Create a new service account, and grant it G Suite domain-wide delegation. Have the application use it to impersonate the user.
Reveal answer details
Close answer details
Correct answerD
Explanationhttps://developers.google.com/admin-sdk/directory/v1/guides/delegation
Question 12
Single choice
You are responsible for protecting highly sensitive data in BigQuery. Your operations teams need access to this data, but given privacy regulations, you want to ensure that they cannot read the sensitive fields such as email addresses and first names. These specific sensitive fields should only be available on a need-to-know basis to the HR team. What should you do?
-
A
Perform data masking with the DLP API and store that data in BigQuery for later use.
-
B
Perform data redaction with the DLP API and store that data in BigQuery for later use.
-
C
Perform data inspection with the DLP API and store that data in BigQuery for later use.
-
D
Perform tokenization for Pseudonymization with the DLP API and store that data in BigQuery for later use.
Reveal answer details
Close answer details
Correct answerD
ExplanationPseudonymization is a de-identification technique that replaces sensitive data values with cryptographically generated tokens. Pseudonymization is widely used in industries like finance and healthcare to help reduce the risk of data in use, narrow compliance scope, and minimize the exposure of sensitive data to systems while preserving data utility and accuracy. https://cloud.google.com/dlp/docs/pseudonymization
Question 13
Single choice
Your organization must store highly sensitive data within Google Cloud. You need to design a solution that provides the strongest level of security and control. What should you do?
-
A
Use Cloud Storage with customer-supplied encryption keys (CSEK), VPC Service Controls for network isolation, and Cloud DLP for data inspection.
-
B
Use Cloud Storage with customer-managed encryption keys (CMEK), Cloud DLP for data classification, and Secret Manager for storing API access tokens.
-
C
Use Cloud Storage with client-side encryption, Cloud KMS for key management, and Cloud HSM for cryptographic operations.
-
D
Use Cloud Storage with server-side encryption, BigQuery with column-level encryption, and IAM roles for access control.
Reveal answer details
Close answer details
Correct answerC
ExplanationWhen dealing with highly sensitive data, client-side encryption provides the strongest level of security because the data is encrypted before it is sent to Google Cloud, ensuring that Google cannot access the plaintext data. The use of Cloud KMS (Key Management Service) for managing encryption keys ensures that you maintain control over key management, and Cloud HSM (Hardware Security Module) adds an additional layer of protection by performing cryptographic operations in dedicated, tamper-evident hardware. This solution ensures: 1. Client-side encryption: Data is encrypted before reaching Google Cloud, so Google never has access to the unencrypted data. 2. Cloud KMS: You manage the keys that encrypt and decrypt data, giving you control over key lifecycle and policies. 3. Cloud HSM: For highly secure key storage and cryptographic operations, providing hardware-level security for cryptographic keys.
Question 14
Single choice
Employees at your company use their personal computers to access your organization's Google Cloud console. You need to ensure that users can only access the Google Cloud console from their corporate-issued devices and verify that they have a valid enterprise certificate. What should you do?
-
A
Implement an Access Policy in BeyondCorp Enterprise to verify the device certificate. Create an access binding with the access policy just created.
-
B
Implement a VPC firewall policy. Activate packet inspection and create an allow rule to validate and verify the device certificate.
-
C
Implement an organization policy to verify the certificate from the access context.
-
D
Implement an Identity and Access Management (IAM) conditional policy to verify the device certificate.
Reveal answer details
Close answer details
Correct answerA
ExplanationA. Implement an Access Policy in BeyondCorp Enterprise to verify the device certificate. Create an access binding with the access policy just created. This approach is designed to enforce zero-trust access policies, making it a strong fit for the stated needs of only allowing access from corporate-issued devices with valid enterprise certificates.
Question 15
Multiple choice
You are setting up a CI/CD pipeline to deploy containerized applications to your production clusters on Google Kubernetes Engine (GKE). You need to prevent containers with known vulnerabilities from being deployed. You have the following requirements for your solution: 1. Must be cloud-native 2. Must be cost-efficient 3. Minimize operational overhead How should you accomplish this? (Choose two.)
-
A
Create a Cloud Build pipeline that will monitor changes to your container templates in a Cloud Source Repositories repository. Add a step to analyze Container Analysis results before allowing the build to continue.
-
B
Use a Cloud Function triggered by log events in Google Cloud's operations suite to automatically scan your container images in Container Registry.
-
C
Use a cron job on a Compute Engine instance to scan your existing repositories for known vulnerabilities and raise an alert if a non-compliant container image is found.
-
D
Deploy Jenkins on GKE and configure a CI/CD pipeline to deploy your containers to Container Registry. Add a step to validate your container images before deploying your container to the cluster.
-
E
In your CI/CD pipeline, add an attestation on your container image when no vulnerabilities have been found. Use a Binary Authorization policy to block deployments of containers with no attestation in your cluster.
Reveal answer details
Close answer details
Correct answersA, E
ExplanationReferences: https://cloud.google.com/architecture/prep-kubernetes-engine-for-prod https://cloud.google.com/container-analysis/docs/container-analysisContainerAnalysisisaservicethatprovidesvulnerabilityscanningandmetadatastorageforcontainers.ThescanningserviceperformsvulnerabilityscansonimagesinContainerRegistryandArtifactRegistry,thenstorestheresultingmetadataandmakesitavailableforconsumptionthroughanAPI. https://cloud.google.com/binary-authorization/docs/attestations After a container image is built, an attestation can be created to affirm that a required activity was performed on the image such as a regression test, vulnerability scan, or other test. The attestation is created by signing the image's unique digest. During deployment, instead of repeating the activities, Binary Authorization verifies the attestations using an attestor. If all of the attestations for an image are verified, Binary Authorization allows the image to be deployed.
Question 16
Single choice
You work for a financial organization in a highly regulated industry that is subject to active regulatory compliance. To meet compliance requirements, you need to continuously maintain a specific set of configurations, data residency, organizational policies, and personnel data access controls. What should you do?
-
A
Apply an organizational policy constraint at the organization level to limit the location of new resource creation.
-
B
Create an Assured Workloads folder for your required compliance program to apply defined controls and requirements.
-
C
Go to the Compliance page in Security Command Center. View the report for your status against the required compliance standard. Triage violations to maintain compliance on a regular basis.
-
D
Create a posture.yaml file with the required security compliance posture. Apply the posture with the gcloud scc postures create POSTURE_NAME --posture-from-file=posture.yaml command in Security Command Center Premium.
Reveal answer details
Close answer details
Correct answerB
ExplanationIn highly regulated industries, compliance with strict standards related to data residency, organizational policies, and access controls is critical. Assured Workloads in Google Cloud is specifically designed to help organizations in regulated industries meet these requirements. It enforces the necessary security controls and compliance requirements by providing predefined compliance environments (such as FedRAMP, PCI-DSS, or HIPAA) and helps maintain compliance through automated processes. By creating an Assured Workloads folder, you can apply all required controls and restrictions for regulatory compliance, including data residency restrictions, personnel access controls, and other security measures. This is the most comprehensive solution to ensure that your organization remains compliant with active regulations.
Question 17
Single choice
An organization's typical network and security review consists of analyzing application transit routes, request handling, and firewall rules. They want to enable their developer teams to deploy new applications without the overhead of this full review. How should you advise this organization?
-
A
Use Forseti with Firewall filters to catch any unwanted configurations in production.
-
B
Mandate use of infrastructure as code and provide static analysis in the CI/CD pipelines to enforce policies.
-
C
Route all VPC traffic through customer-managed routers to detect malicious patterns in production.
-
D
All production applications will run on-premises. Allow developers free rein in GCP as their dev and QA platforms.
Reveal answer details
Close answer details
Correct answerB
Explanationhttps://cloud.google.com/recommender/docs/tutorial-iac
Question 18
Single choice
You have the following resource hierarchy. There is an organization policy at each node in the hierarchy as shown. Which load balancer types are denied in VPC A? 
-
A
All load balancer types are denied in accordance with the global node's policy.
-
B
INTERNAL_TCP_UDP, INTERNAL_HTTP_HTTPS is denied in accordance with the folder's policy.
-
C
EXTERNAL_TCP_PROXY, EXTERNAL_SSL_PROXY are denied in accordance with the project's policy.
-
D
EXTERNAL_TCP_PROXY, EXTERNAL_SSL_PROXY, INTERNAL_TCP_UDP, and INTERNAL_HTTP_HTTPS are denied in accordance with the folder and project's policies.
Reveal answer details
Close answer details
Question 19
Multiple choice
A company is running workloads in a dedicated server room. They must only be accessed from within the private company network. You need to connect to these workloads from Compute Engine instances within a Google Cloud Platform project. Which two approaches can you take to meet the requirements? (Choose two.)
-
A
Configure the project with Cloud VPN.
-
B
Configure the project with Shared VPC.
-
C
Configure the project with Cloud Interconnect.
-
D
Configure the project with VPC peering.
-
E
Configure all Compute Engine instances with Private Access.
Reveal answer details
Close answer details
Correct answersA, C
ExplanationA) IPsec VPN tunels: https://cloud.google.com/network-connectivity/docs/vpn/concepts/overviewInterconnect https://cloud.google.com/network-connectivity/docs/interconnect/concepts/dedicated-overview https://cloud.google.com/solutions/secure-data-workloads-use-cases
Question 20
Single choice
An administrative application is running on a virtual machine (VM) in a managed group at port 5601 inside a Virtual Private Cloud (VPC) instance without access to the internet currently. You want to expose the web interface at port 5601 to users and enforce authentication and authorization Google credentials. What should you do?
-
A
Configure the bastion host with OS Login enabled and allow connection to port 5601 at VPC firewall. Log in to the bastion host from the Google Cloud console by using SSH-in-browser and then to the web application.
-
B
Modify the VPC routing with the default route point to the default internet gateway. Modify the VPC Firewall rule to allow access from the internet 0.0.0.0/0 to port 5601 on the application instance.
-
C
Configure Secure Shell Access (SSH) bastion host in a public network, and allow only the bastion host to connect to the application on port 5601. Use a bastion host as a jump host to connect to the application.
-
D
Configure an HTTP Load Balancing instance that points to the managed group with Identity-Aware Proxy (IAP) protection with Google credentials. Modify the VPC firewall to allow access from IAP network range.
Reveal answer details
Close answer details
Correct answerD
ExplanationConfigure an HTTP Load Balancing instance that points to the managed group with Identity-Aware Proxy (IAP) protection with Google credentials. Modify the VPC firewall to allow access from IAP network range. This approach allows you to expose the web interface securely by using Identity-Aware Proxy (IAP), which provides authentication and authorization with Google credentials. The HTTP Load Balancer can distribute traffic to the VMs in the managed group, and the VPC firewall rule ensures that access is allowed from the IAP network range.
Question 21
Single choice
You have numerous private virtual machines on Google Cloud. You occasionally need to manage the servers through Secure Socket Shell (SSH) from a remote location. You want to configure remote access to the servers in a manner that optimizes security and cost efficiency. What should you do?
-
A
Create a site-to-site VPN from your corporate network to Google Cloud.
-
B
Configure server instances with public IP addresses Create a firewall rule to only allow traffic from your corporate IPs.
-
C
Create a firewall rule to allow access from the Identity-Aware Proxy (IAP) IP range Grant the role of an IAP-secured Tunnel User to the administrators.
-
D
Create a jump host instance with public IP Manage the instances by connecting through the jump host.
Reveal answer details
Close answer details
Question 22
Single choice
Your team needs to make sure that their backend database can only be accessed by the frontend application and no other instances on the network. How should your team design this network?
-
A
Create an ingress firewall rule to allow access only from the application to the database using firewall tags.
-
B
Create a different subnet for the frontend application and database to ensure network isolation.
-
C
Create two VPC networks, and connect the two networks using Cloud VPN gateways to ensure network isolation.
-
D
Create two VPC networks, and connect the two networks using VPC peering to ensure network isolation.
Reveal answer details
Close answer details
Correct answerA
Explanation"However, even though it is possible to uses tags for target filtering in this manner, we recommend that you use service accounts where possible. Target tags are not access-controlled and can be changed by someone with the instanceAdmin role while VMs are in service. Service accounts are access-controlled, meaning that a specific user must be explicitly authorized to use a service account. There can only be one service account per instance, whereas there can be multiple tags. Also, service accounts assigned to a VM can only be changed when the VM is stopped"
Question 23
Single choice
Your organization operates in a highly regulated environment and has a stringent set of compliance requirements for protecting customer data. You must encrypt data while in use to meet regulations. What should you do?
-
A
Enable the use of customer-supplied encryption keys (CSEK) keys in the Google Compute Engine VMs to give your organization maximum control over their VM disk encryption.
-
B
Establish a trusted execution environment with a Confidential VM.
-
C
Use a Shielded VM to ensure a secure boot with integrity monitoring for the application environment.
-
D
Use customer-managed encryption keys (CMEK) and Cloud KSM to enable your organization to control their keys for data encryption in Cloud SQL.
Reveal answer details
Close answer details
Correct answerB
ExplanationIn a highly regulated environment with stringent compliance requirements for protecting customer data, encryption of data while in use (i.e., during processing) is a critical aspect of security. Google Cloud's Confidential VMs provide a trusted execution environment by encrypting data while it is being processed, which ensures that even Google Cloud and other external entities cannot access the data during its use. This level of protection is crucial in meeting strict compliance regulations related to data privacy and security. Confidential VMs use hardware-based encryption to protect the integrity and confidentiality of data being processed, making it the best solution for scenarios where data must remain encrypted even while in use.
Question 24
Single choice
You are part of a security team investigating a compromised service account key. You need to audit which new resources were created by the service account. What should you do?
-
A
-
B
Query Admin Activity logs.
-
C
Query Access Transparency logs.
-
D
Query Stackdriver Monitoring Workspace.
Reveal answer details
Close answer details
Correct answerB
ExplanationAdmin activity logs are always created to log entries for API calls or other actions that modify the configuration or metadata of resources. For example, these logs record when users create VM instances or change Identity and Access Management permissions. References: https://cloud.google.com/iam/docs/audit-logging/examples-service-accounts
Question 25
Multiple choice
Your company's new CEO recently sold two of the company's divisions. Your Director asks you to help migrate the Google Cloud projects associated with those divisions to a new organization node. Which preparation steps are necessary before this migration occurs? (Choose two.)
-
A
Remove all project-level custom Identity and Access Management (IAM) roles.
-
B
Disallow inheritance of organization policies.
-
C
Identify inherited Identity and Access Management (IAM) roles on projects to be migrated.
-
D
Create a new folder for all projects to be migrated.
-
E
Remove the specific migration projects from any VPC Service Controls perimeters and bridges.
Reveal answer details
Close answer details
Question 26
Single choice
Your organization hosts a financial services application running on Compute Engine instances for a third-party company. The third-party company's servers that will consume the application also run on Compute Engine in a separate Google Cloud organization. You need to configure a secure network connection between the Compute Engine instances. You have the following requirements: 1. The network connection must be encrypted. 2. The communication between servers must be over private IP addresses. What should you do?
-
A
Configure a Cloud VPN connection between your organization's VPC network and the third party's that is controlled by VPC firewall rules.
-
B
Configure a VPC peering connection between your organization's VPC network and the third party's that is controlled by VPC firewall rules.
-
C
Configure a VPC Service Controls perimeter around your Compute Engine instances, and provide access to the third party via an access level.
-
D
Configure an Apigee proxy that exposes your Compute Engine-hosted application as an API, and is encrypted with TLS which allows access only to the third party.
Reveal answer details
Close answer details
Correct answerB
ExplanationGoogle encrypts and authenticates data in transit at one or more network layers when data moves outside physical boundaries not controlled by Google or on behalf of Google. All VM-to-VM traffic within a VPC network and peered VPC networks is encrypted. https://cloud.google.com/docs/security/encryption-in-transit#cio-level_summary
Question 27
Single choice
An organization's security and risk management teams are concerned about where their responsibility lies for certain production workloads they are running in Google Cloud Platform (GCP), and where Google's responsibility lies. They are mostly running workloads using Google Cloud's Platform-as-a-Service (PaaS) offerings, including App Engine primarily. Which one of these areas in the technology stack would they need to focus on as their primary responsibility when using App Engine?
-
A
Configuring and monitoring VPC Flow Logs
-
B
Defending against XSS and SQLi attacks
-
C
Manage the latest updates and security patches for the Guest OS
-
D
Encrypting all stored data
Reveal answer details
Close answer details
Correct answerB
Explanationin PaaS the customer is responsible for web app security, deployment, usage, access policy, and content. https://cloud.google.com/architecture/framework/security/shared-responsibility-shared-fate
Question 28
Single choice
You have an application where the frontend is deployed on a managed instance group in subnet A and the data layer is stored on a mysql Compute Engine virtual machine (VM) in subnet B on the same VPC. Subnet A and Subnet B hold several other Compute Engine VMs. You only want to allow thee application frontend to access the data in the application's mysql instance on port 3306. What should you do?
-
A
Configure an ingress firewall rule that allows communication from the src IP range of subnet A to the tag "data-tag" that is applied to the mysql Compute Engine VM on port 3306.
-
B
Configure an ingress firewall rule that allows communication from the frontend's unique service account to the unique service account of the mysql Compute Engine VM on port 3306.
-
C
Configure a network tag "fe-tag" to be applied to all instances in subnet A and a network tag "data-tag" to be applied to all instances in subnet B. Then configure an egress firewall rule that allows communication from Compute Engine VMs tagged with data-tag to destination Compute Engine VMs tagged fe-tag.
-
D
Configure a network tag "fe-tag" to be applied to all instances in subnet A and a network tag "data-tag" to be applied to all instances in subnet B. Then configure an ingress firewall rule that allows communication from Compute Engine VMs tagged with fe-tag to destination Compute Engine VMs tagged with data-tag.
Reveal answer details
Close answer details
Correct answerB
Explanationhttps://cloud.google.com/sql/docs/mysql/sql-proxy#using-a-service-account
Question 29
Single choice
Last week, a company deployed a new App Engine application that writes logs to BigQuery. No other workloads are running in the project. You need to validate that all data written to BigQuery was done using the App Engine Default Service Account. What should you do?
-
A
1. Use StackDriver Logging and filter on BigQuery Insert Jobs. 2. Click on the email address in line with the App Engine Default Service Account in the authentication field. 3. Click Hide Matching Entries. 4. Make sure the resulting list is empty.
-
B
1. Use StackDriver Logging and filter on BigQuery Insert Jobs. 2. Click on the email address in line with the App Engine Default Service Account in the authentication field. 3. Click Show Matching Entries. 4. Make sure the resulting list is empty.
-
C
1. In BigQuery, select the related dataset. 2. Make sure the App Engine Default Service Account is the only account that can write to the dataset.
-
D
1. Go to the IAM section on the project. 2. Validate that the App Engine Default Service Account is the only account that has a role that can write to BigQuery.
Reveal answer details
Close answer details
Question 30
Single choice
You are creating a secure network architecture. You must fully isolate development and production environments, and prevent any network traffic between the two environments. The network team requires that there is only one central entry point to the cloud network from the on-premises environment. What should you do?
-
A
Create one Virtual Private Cloud (VPC) network per environment. Add the on-premises entry point to the production VPC. Peer the VPCs with each other and create firewall rules to prevent traffic.
-
B
Create one shared Virtual Private Cloud (VPC) network and use it as the entry point to the cloud network. Create separate subnets per environment. Create firewall rules to prevent traffic.
-
C
Create one Virtual Private Cloud (VPC) network per environment. Create a VPC Service Controls perimeter per environment and add one environment VPC to each.
-
D
Create one Virtual Private Cloud (VPC) network per environment. Create one additional VPC for the entry point to the cloud network. Peer the entry point VPC with the environment VPCs.
Reveal answer details
Close answer details
Question 31
Single choice
An organization receives an increasing number of phishing emails. Which method should be used to protect employee credentials in this situation?
-
A
Multifactor Authentication
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
Explanationhttps://cloud.google.com/blog/products/g-suite/7-ways-admins-can-help-secure-accounts-against-phishing-g-suite
Question 32
Single choice
You have stored company approved compute images in a single Google Cloud project that is used as an image repository. This project is protected with VPC Service Controls and exists in the perimeter along with other projects in your organization. This lets other projects deploy images from the image repository project. A team requires deploying a third-party disk image that is stored in an external Google Cloud organization. You need to grant read access to the disk image so that it can be deployed into the perimeter. What should you do?
-
A
Allow the external project by using the organizational policy, constraints/compute.trustedImageProjects.
-
B
1. Update the perimeter. 2. Configure the egressTo field to include the external Google Cloud project number as an allowed resource and the serviceName to compute.googleapis.com. 3. Configure the egressFrom field to set identityType to ANY_IDENTITY
-
C
1. Update the perimeter. 2. Configure the ingressFrom field to set identityType to ANY_IDENTITY. 3. Configure the ingressTo field to include the external Google Cloud project number as an allowed resource and the serviceName to compute.googleapis.com.
-
D
1. Update the perimeter. 2. Configure the egressTo field to set identityType to ANY_IDENTITY. 3. Configure the egressFrom field to include the external Google Cloud project number as an allowed resource and the serviceName to compute.googleapis.com.
Reveal answer details
Close answer details
Question 33
Single choice
Your organization is building a real-time recommendation engine using ML models that process live user activity data stored in BigQuery and Cloud Storage. Each new model developed is saved to Artifact Registry. This new system deploys models to Google Kubernetes Engine, and uses Pub/Sub for message queues. Recent industry news have been reporting attacks exploiting ML model supply chains. You need to enhance the security in this serverless architecture, specifically against risks to the development and deployment pipeline. What should you do?
-
A
Enable container image vulnerability scanning during development and pre-deployment. Enforce Binary Authorization on images deployed from Artifact Registry to your continuous integration and continuous deployment (CVCD) pipeline.
-
B
Thoroughly sanitize all training data prior to model development to reduce risk of poisoning attacks. Use IAM for authorization, and apply role-based restrictions to code repositories and cloud services.
-
C
Limit external libraries and dependencies that are used for the ML models as much as possible. Continuously rotate encryption keys that are used to access the user data from BigQuery and Cloud Storage.
-
D
Develop strict firewall rules to limit external traffic to Cloud Run instances. Integrate intrusion detection systems (IDS) for real-time anomaly detection on Pub/Sub message flows.
Reveal answer details
Close answer details
Correct answerA
ExplanationIn response to the growing threat of attacks on the ML model supply chain, the key focus should be securing the entire development and deployment pipeline, especially when deploying models in containers, as well as ensuring that only trusted, vulnerability-free artifacts are deployed. Enabling container image vulnerability scanning: This helps detect and mitigate security risks in the containers that host your ML models during the development phase and prior to deployment. Vulnerability scanning checks for known issues in dependencies and libraries, ensuring that any weaknesses are identified and fixed before deployment. Enforcing Binary Authorization: This feature ensures that only trusted and verified container images can be deployed. It helps prevent the deployment of compromised images or models that may have been tampered with in the supply chain. By enforcing Binary Authorization, you add an additional layer of security to your deployment process, protecting the integrity of your ML models.
Question 34
Single choice
Your team sets up a Shared VPC Network where project co-vpc-prod is the host project. Your team has configured the firewall rules, subnets, and VPN gateway on the host project. They need to enable Engineering Group A to attach a Compute Engine instance to only the 10.1.1.0/24 subnet. What should your team grant to Engineering Group A to meet this requirement?
-
A
Compute Network User Role at the host project level.
-
B
Compute Network User Role at the subnet level.
-
C
Compute Shared VPC Admin Role at the host project level.
-
D
Compute Shared VPC Admin Role at the service project level.
Reveal answer details
Close answer details
Correct answerB
Explanationhttps://cloud.google.com/vpc/docs/shared-vpc#svc_proj_admins
Question 35
Single choice
Your Google Cloud organization is subdivided into three folders: production, development, and networking, Networking resources for the organization are centrally managed in the networking folder. You discovered that projects in the production folder are attaching to Shared VPCs that are outside of the networking folder which could become a data exfiltration risk. You must resolve the production folder issue without impacting the development folder. You need to use the most efficient and least disruptive approach. What should you do?
-
A
Enable the Restrict Shared VPC Host Projects organization policy on the production folder. Create a custom rule and configure the policy type to Allow. In the Custom value section, enter under:folders/ networking.
-
B
Enable the Restrict Shared VPC Host Projects organization policy on the networking folder only. Create a new custom rule and configure the policy type to Allow. In the Custom value section, enter under:organizations/123456739123.
-
C
Enable the Restrict Shared VPC Host Projects organization policy at the project level for each of the production projects. Create a custom rule and configure the policy type to Allow. In the Custom value section, enter under:folders/ networking.
-
D
Enable the Restrict Shared VPC Host Projects organization policy at the organization level. Create a custom rule and configure the policy type to Allow. In the Custom value section, enter under:folders/ networking.
Reveal answer details
Close answer details
Correct answerA
ExplanationThe most efficient and least disruptive way to solve the issue is to apply the Restrict Shared VPC Host Projects organization policy specifically to the production folder. This option directly addresses the issue in the production folder without impacting the development folder, making it the least disruptive and most efficient approach. By enabling the Restrict Shared VPC Host Projects organization policy at the production folder level, you can prevent projects in the production folder from attaching to Shared VPCs that are outside of the networking folder, thereby mitigating the risk of data exfiltration. The custom rule ensures that only Shared VPC host projects in the networking folder can be used by the production projects, which achieves the goal while maintaining existing workflows for the development folder.
Question 36
Single choice
Your company wants to determine what products they can build to help customers improve their credit scores depending on their age range. To achieve this, you need to join user information in the company's banking app with customers' credit score data received from a third party. While using this raw data will allow you to complete this task, it exposes sensitive data, which could be propagated into new systems. This risk needs to be addressed using de-identification and tokenization with Cloud Data Loss Prevention while maintaining the referential integrity across the database. Which cryptographic token format should you use to meet these requirements?
-
A
-
B
-
C
Format-preserving encryption
-
D
Reveal answer details
Close answer details
Correct answerA
Explanation"This encryption method is reversible, which helps to maintain referential integrity across your database and has no character-set limitations." https://cloud.google.com/blog/products/identity-security/take-charge-of-your-data-how-tokenization-makes- data-usable-without-sacrificing-privacy https://cloud.google.com/dlp/docs/pseudonymization FPE provides fewer security guarantees compared to other deterministic encryption methods such as AES-SIV. For these reasons, Google strongly recommends using deterministic encryption with AES-SIV instead of FPE for all security sensitive use cases. Other methods like deterministic encryption using AES-SIV provide these stronger security guarantees and are recommended for tokenization use cases unless length and character set preservation are strict requirements--for example, for backward compatibility with a legacy data system.
Question 37
Single choice
Your organization has sensitive data stored in BigQuery and Cloud Storage. You need to design a solution that provides granular and flexible control authorization to read data. What should you do?
-
A
Deidentify sensitive fields within the dataset by using data leakage protection within the Sensitive Data Protection services.
-
B
Use Cloud External Key Manager (Cloud EKM) to encrypt the data in BigQuery and Cloud Storage.
-
C
Grant identity and access management (IAM) roles and permissions to principals.
-
D
Enable server-side encryption on the data in BigQuery and Cloud Storage.
Reveal answer details
Close answer details
Question 38
Single choice
You are setting up a new Cloud Storage bucket in your environment that is encrypted with a customer managed encryption key (CMEK). The CMEK is stored in Cloud Key Management Service (KMS), in project "prj-a", and the Cloud Storage bucket will use project "prj-b". The key is backed by a Cloud Hardware Security Module (HSM) and resides in the region europe-west3. Your storage bucket will be located in the region europe-west1. When you create the bucket, you cannot access the key, and you need to troubleshoot why. What has caused the access issue?
-
A
A firewall rule prevents the key from being accessible.
-
B
Cloud HSM does not support Cloud Storage.
-
C
The CMEK is in a different project than the Cloud Storage bucket.
-
D
The CMEK is in a different region than the Cloud Storage bucket.
Reveal answer details
Close answer details
Correct answerD
ExplanationThe CMEK is in a different region than the Cloud Storage bucket. When you use a customer-managed encryption key (CMEK) to secure a Cloud Storage bucket, the key and the bucket must be located in the same region. In this case, the key is in europe-west3 and the bucket is in europe-west1, which is why you're unable to access the key.
Question 39
Single choice
You are the security admin of your company. Your development team creates multiple GCP projects under the "implementation" folder for several dev, staging, and production workloads. You want to prevent data exfiltration by malicious insiders or compromised code by setting up a security perimeter. However, you do not want to restrict communication between the projects. What should you do?
-
A
Use a Shared VPC to enable communication between all projects, and use firewall rules to prevent data exfiltration.
-
B
Create access levels in Access Context Manager to prevent data exfiltration, and use a shared VPC for communication between projects.
-
C
Use an infrastructure-as-code software tool to set up a single service perimeter and to deploy a Cloud Function that monitors the "implementation" folder via Stackdriver and Cloud Pub/Sub. When the function notices that a new project is added to the folder, it executes Terraform to add the new project to the associated perimeter.
-
D
Use an infrastructure-as-code software tool to set up three different service perimeters for dev, staging, and prod and to deploy a Cloud Function that monitors the "implementation" folder via Stackdriver and Cloud Pub/Sub. When the function notices that a new project is added to the folder, it executes Terraform to add the new project to the respective perimeter.
Reveal answer details
Close answer details
Correct answerC
Explanationhttps://cloud.google.com/vpc-service-controls/docs/overview#benefits https://github.com/terraform-google-modules/terraform-google-vpc-service-controls/tree/master/examples/ automatic_folder
Question 40
Single choice
You are managing a Google Cloud environment that is organized into folders that represent different teams. These teams need the flexibility to modify organization policies relevant to their work. You want to grant the teams the necessary permissions while upholding Google-recommended security practices and minimizing administrative complexity. What should you do?
-
A
Create a custom IAM role with the organization policy administrator permission and grant the permission to each team's folder. Limit policy modifications based on folder names within the custom role's definition.
-
B
Assign the organization policy administrator role to a central service account and provide teams with the credentials to use the service account when needed.
-
C
Create an organization-level tag. Attach the tag to relevant folders. Use an IAM condition to restrict the organization policy administrator role to resources with that tag.
-
D
Grant each team the organization policy administrator role at the organization level.
Reveal answer details
Close answer details
Question 41
Single choice
Your organization is moving virtual machines (VMs) to Google Cloud. You must ensure that operating system images that are used across your projects are trusted and meet your security requirements. What should you do?
-
A
Implement an organization policy to enforce that boot disks can only be created from images that come from the trusted image project.
-
B
Create a Cloud Function that is automatically triggered when a new virtual machine is created from the trusted image repository Verify that the image is not deprecated.
-
C
Implement an organization policy constraint that enables the Shielded VM service on all projects to enforce the trusted image repository usage.
-
D
Automate a security scanner that verifies that no common vulnerabilities and exposures (CVEs) are present in your trusted image repository.
Reveal answer details
Close answer details
Question 42
Single choice
You are using Security Command Center (SCC) to protect your workloads and receive alerts for suspected security breaches at your company. You need to detect cryptocurrency mining software. Which SCC service should you use?
-
A
Container Threat Detection
-
B
-
C
Rapid Vulnerability Detection
-
D
Virtual Machine Threat Detection
Reveal answer details
Close answer details
Question 43
Single choice
An employer wants to track how bonus compensations have changed over time to identify employee outliers and correct earning disparities. This task must be performed without exposing the sensitive compensation data for any individual and must be reversible to identify the outlier. Which Cloud Data Loss Prevention API technique should you use to accomplish this?
-
A
-
B
-
C
Format-preserving encryption
-
D
Reveal answer details
Close answer details
Question 44
Single choice
You are working with developers to secure custom training jobs running on Vertex AI. For compliance reasons, all supported data types must be encrypted by key materials that reside in the Europe region and are controlled by your organization. The encryption activity must not impact the training operation in Vertex AI. What should you do?
-
A
Encrypt the code, training data, and metadata with Google default encryption. Use customer-managed encryption keys (CMEK) for the trained models exported to Cloud Storage buckets.
-
B
Encrypt the code, training data, metadata, and exported trained models with customer-managed encryption keys (CMEK).
-
C
Encrypt the code, training data, and exported trained models with customer-managed encryption keys (CMEK).
-
D
Encrypt the code, training data, and metadata with Google default encryption. Implement an organization policy that enforces a constraint to restrict the Cloud KMS location to the Europe region.
Reveal answer details
Close answer details
Question 45
Single choice
Your organization's use of the Google Cloud has grown substantially and there are many different groups using different cloud resources independently. You must identify common misconfigurations and compliance violations across the organization and track findings for remedial action in a dashboard. What should you do?
-
A
Create a filter set in Cloud Asset Inventory to identify service accounts with high privileges and IAM principals with Gmail domains.
-
B
Scan and alert vulnerabilities and misconfigurations by using Secure Health Analytics detectors in Security Command Center Premium.
-
C
Set up filters on Cloud Audit Logs to flag log entries for specific, risky API calls, and display the calls in a Cloud Log Analytics dashboard.
-
D
Alert and track emerging attacks detected in your environment by using Event Threat Detection detectors.
Reveal answer details
Close answer details
Question 46
Single choice
You are a consultant for an organization that is considering migrating their data from its private cloud to Google Cloud. The organization's compliance team is not familiar with Google Cloud and needs guidance on how compliance requirements will be met on Google Cloud. One specific compliance requirement is for customer data at rest to reside within specific geographic boundaries. Which option should you recommend for the organization to meet their data residency requirements on Google Cloud?
-
A
Organization Policy Service constraints
-
B
-
C
-
D
Geolocation access controls
-
E
Reveal answer details
Close answer details
Correct answerA
Explanationhttps://cloud.google.com/resource-manager/docs/organization-policy/using-constraints#list-constraint
Question 47
Single choice
You want to limit the images that can be used as the source for boot disks. These images will be stored in a dedicated project. What should you do?
-
A
Use the Organization Policy Service to create a compute.trustedimageProjects constraint on the organization level. List the trusted project as the whitelist in an allow operation.
-
B
Use the Organization Policy Service to create a compute.trustedimageProjects constraint on the organization level. List the trusted projects as the exceptions in a deny operation.
-
C
In Resource Manager, edit the project permissions for the trusted project. Add the organization as member with the role: Compute Image User.
-
D
In Resource Manager, edit the organization permissions. Add the project ID as member with the role: Compute Image User.
Reveal answer details
Close answer details
Correct answerA
Explanationhttps://cloud.google.com/compute/docs/images/restricting-image-access#trusted_images https://cloud.google.com/compute/docs/images/restricting-image-access
Question 48
Multiple choice
You need to provide a corporate user account in Google Cloud for each of your developers and operational staff who need direct access to GCP resources. Corporate policy requires you to maintain the user identity in a third-party identity management provider and leverage single sign-on. You learn that a significant number of users are using their corporate domain email addresses for personal Google accounts, and you need to follow Google recommended practices to convert existing unmanaged users to managed accounts. Which two actions should you take? (Choose two.)
-
A
Use Google Cloud Directory Sync to synchronize your local identity management system to Cloud Identity.
-
B
Use the Google Admin console to view which managed users are using a personal account for their recovery email.
-
C
Add users to your managed Google account and force users to change the email addresses associated with their personal accounts.
-
D
Use the Transfer Tool for Unmanaged Users (TTUU) to find users with conflicting accounts and ask them to transfer their personal Google accounts.
-
E
Send an email to all of your employees and ask those users with corporate email addresses for personal Google accounts to delete the personal accounts immediately.
Reveal answer details
Close answer details
Correct answersA, D
Explanationhttps://cloud.google.com/architecture/identity/migrating-consumer-accounts#initiating_a_transfer
Question 49
Multiple choice
Your organization strives to be a market leader in software innovation. You provided a large number of Google Cloud environments so developers can test the integration of Gemini in Vertex AI into their existing applications or create new projects. Your organization has 200 developers and a five-person security team. You must prevent and detect proper security policies across the Google Cloud environments. What should you do? (Choose two.)
-
A
Apply organization policy constraints. Detect and monitor drifts by using Security Health Analytics.
-
B
Publish internal policies and clear guidelines to securely develop applications.
-
C
Use Cloud Logging to create log filters to detect misconfigurations. Trigger Cloud Run functions to remediate misconfigurations.
-
D
Apply a predefined AI-recommended security posture template for Gemini in Vertex AI in Security Command Center Enterprise or Premium tiers.
-
E
Implement the least privileged access Identity and Access Management roles to prevent misconfigurations.
Reveal answer details
Close answer details
Correct answersA, C
ExplanationIn a scenario where you have many developers and a small security team, it's essential to automate as much as possible to prevent and detect security issues across Google Cloud environments. Let's look at both correct choices in detail: Apply organization policy constraints. Detect and monitor drifts by using Security Health Analytics: 1. Organization policies allow you to centrally enforce security requirements across all Google Cloud projects. By applying policy constraints, you can restrict what developers can and cannot do, helping to maintain a secure baseline. 2. Security Health Analytics (SHA) continuously scans for security misconfigurations and compliance issues in your cloud environments. Using SHA ensures that policy violations or drifts from security best practices are detected automatically and can be monitored effectively. Use Cloud Logging to create log filters to detect misconfigurations. Trigger Cloud Run functions to remediate misconfigurations: 1. Cloud Logging enables the creation of custom log filters that can detect specific misconfigurations or security policy violations. This helps in real-time monitoring of cloud environments. 2. Cloud Run functions can be triggered by log events to automatically remediate misconfigurations, ensuring that any deviations from your security policies are corrected quickly without manual intervention. This approach helps the small security team keep up with the large number of developers.
|