πŸ”

PCSE β€” questions

Page 6 of 18 Β· 356 total questions.

Topic 1 Β· Question 101

Your company wants to determine what products they can build to help customers improve their credit scores depending on their age range. To achieve this, you need to join user information in the company's banking app with customers' credit score data received from a third party. While using this raw data will allow you to complete this task, it exposes sensitive data, which could be propagated into new systems. This risk needs to be addressed using de-identification and tokenization with Cloud Data Loss Prevention while maintaining the referential integrity across the database. Which cryptographic token format should you use to meet these requirements?

  • ADeterministic encryption (correct answer)
  • BSecure, key-based hashes
  • CFormat-preserving encryption
  • DCryptographic hashing
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Deterministic encryption.

Topic 1 Β· Question 102 Β· Select all that apply

An office manager at your small startup company is responsible for matching payments to invoices and creating billing alerts. For compliance reasons, the office manager is only permitted to have the Identity and Access Management (IAM) permissions necessary for these tasks. Which two IAM roles should the office manager have? (Choose two.)

  • AOrganization Administrator
  • BProject Creator
  • CBilling Account Viewer (correct answer)
  • DBilling Account Costs Manager (correct answer)
  • EBilling Account User
Reveal answer & explanation
Correct answer: C, D

The correct answer is C, D. Option C: Billing Account Viewer Option D: Billing Account Costs Manager.

Topic 1 Β· Question 103

You are designing a new governance model for your organization's secrets that are stored in Secret Manager. Currently, secrets for Production and Non- Production applications are stored and accessed using service accounts. Your proposed solution must: β€’ Provide granular access to secrets β€’ Give you control over the rotation schedules for the encryption keys that wrap your secrets β€’ Maintain environment separation β€’ Provide ease of management Which approach should you take?

  • A1. Use separate Google Cloud projects to store Production and Non-Production secrets. 2. Enforce access control to secrets using project-level identity and Access Management (IAM) bindings. 3. Use customer-managed encryption keys to encrypt secrets. (correct answer)
  • B1. Use a single Google Cloud project to store both Production and Non-Production secrets. 2. Enforce access control to secrets using secret-level Identity and Access Management (IAM) bindings. 3. Use Google-managed encryption keys to encrypt secrets.
  • C1. Use separate Google Cloud projects to store Production and Non-Production secrets. 2. Enforce access control to secrets using secret-level Identity and Access Management (IAM) bindings. 3. Use Google-managed encryption keys to encrypt secrets.
  • D1. Use a single Google Cloud project to store both Production and Non-Production secrets. 2. Enforce access control to secrets using project-level Identity and Access Management (IAM) bindings. 3. Use customer-managed encryption keys to encrypt secrets.
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: 1. Use separate Google Cloud projects to store Production and Non-Production secrets. 2. Enforce access control to secrets using project-level identity and Access Management (IAM) bindings. 3. Use customer-managed enc...

Explanation

Cloud IAM grants fine-grained, least-privilege access to Google Cloud resources.

Topic 1 Β· Question 104

You are a security engineer at a finance company. Your organization plans to store data on Google Cloud, but your leadership team is worried about the security of their highly sensitive data. Specifically, your company is concerned about internal Google employees' ability to access your company's data on Google Cloud. What solution should you propose?

  • AUse customer-managed encryption keys.
  • BUse Google's Identity and Access Management (IAM) service to manage access controls on Google Cloud.
  • CEnable Admin activity logs to monitor access to resources.
  • DEnable Access Transparency logs with Access Approval requests for Google employees. (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Enable Access Transparency logs with Access Approval requests for Google employees.

Topic 1 Β· Question 105 Β· Select all that apply

You want to use the gcloud command-line tool to authenticate using a third-party single sign-on (SSO) SAML identity provider. Which options are necessary to ensure that authentication is supported by the third-party identity provider (IdP)? (Choose two.)

  • ASSO SAML as a third-party IdP (correct answer)
  • BIdentity Platform
  • COpenID Connect
  • DIdentity-Aware Proxy
  • ECloud Identity (correct answer)
Reveal answer & explanation
Correct answer: A, E

The correct answer is A, E. Option A: SSO SAML as a third-party IdP Option E: Cloud Identity

Explanation

Cloud Identity manages users, groups, and device policies as a managed identity platform.

Topic 1 Β· Question 106 Β· Select all that apply

You work for a large organization where each business unit has thousands of users. You need to delegate management of access control permissions to each business unit. You have the following requirements: β€’ Each business unit manages access controls for their own projects. β€’ Each business unit manages access control permissions at scale. β€’ Business units cannot access other business units' projects. β€’ Users lose their access if they move to a different business unit or leave the company. β€’ Users and access control permissions are managed by the on-premises directory service. What should you do? (Choose two.)

  • AUse VPC Service Controls to create perimeters around each business unit's project.
  • BOrganize projects in folders, and assign permissions to Google groups at the folder level. (correct answer)
  • CGroup business units based on Organization Units (OUs) and manage permissions based on OUs
  • DCreate a project naming convention, and use Google's IAM Conditions to manage access based on the prefix of project names.
  • EUse Google Cloud Directory Sync to synchronize users and group memberships in Cloud Identity. (correct answer)
Reveal answer & explanation
Correct answer: B, E

The correct answer is B, E. Option B: Organize projects in folders, and assign permissions to Google groups at the folder level. Option E: Use Google Cloud Directory Sync to synchronize users and group memberships in Cloud Identity.

Explanation

Cloud Identity manages users, groups, and device policies as a managed identity platform.

Topic 1 Β· Question 107

Your organization recently deployed a new application on Google Kubernetes Engine. You need to deploy a solution to protect the application. The solution has the following requirements: β€’ Scans must run at least once per week β€’ Must be able to detect cross-site scripting vulnerabilities β€’ Must be able to authenticate using Google accounts Which solution should you use?

  • AGoogle Cloud Armor
  • BWeb Security Scanner (correct answer)
  • CSecurity Health Analytics
  • DContainer Threat Detection
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Web Security Scanner.

Topic 1 Β· Question 108

An organization is moving applications to Google Cloud while maintaining a few mission-critical applications on-premises. The organization must transfer the data at a bandwidth of at least 50 Gbps. What should they use to ensure secure continued connectivity between sites?

  • ADedicated Interconnect (correct answer)
  • BCloud Router
  • CCloud VPN
  • DPartner Interconnect
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Dedicated Interconnect

Explanation

Dedicated Interconnect provides a private physical connection into Google's network.

Topic 1 Β· Question 109

Your organization has had a few recent DDoS attacks. You need to authenticate responses to domain name lookups. Which Google Cloud service should you use?

  • ACloud DNS with DNSSEC (correct answer)
  • BCloud NAT
  • CHTTP(S) Load Balancing
  • DGoogle Cloud Armor
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Cloud DNS with DNSSEC

Explanation

Cloud DNS provides scalable, authoritative DNS with health checks and routing policies.

Topic 1 Β· Question 110

Your Security team believes that a former employee of your company gained unauthorized access to Google Cloud resources some time in the past 2 months by using a service account key. You need to confirm the unauthorized access and determine the user activity. What should you do?

  • AUse Security Health Analytics to determine user activity.
  • BUse the Cloud Monitoring console to filter audit logs by user.
  • CUse the Cloud Data Loss Prevention API to query logs in Cloud Storage.
  • DUse the Logs Explorer to search for user activity. (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Use the Logs Explorer to search for user activity.

Topic 1 Β· Question 111

Your company requires the security and network engineering teams to identify all network anomalies within and across VPCs, internal traffic from VMs to VMs, traffic between end locations on the internet and VMs, and traffic between VMs to Google Cloud services in production. Which method should you use?

  • ADefine an organization policy constraint.
  • BConfigure packet mirroring policies. (correct answer)
  • CEnable VPC Flow Logs on the subnet.
  • DMonitor and analyze Cloud Audit Logs.
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Configure packet mirroring policies.

Topic 1 Β· Question 112

Your company has been creating users manually in Cloud Identity to provide access to Google Cloud resources. Due to continued growth of the environment, you want to authorize the Google Cloud Directory Sync (GCDS) instance and integrate it with your on-premises LDAP server to onboard hundreds of users. You are required to: β€’ Replicate user and group lifecycle changes from the on-premises LDAP server in Cloud Identity. β€’ Disable any manually created users in Cloud Identity. You have already configured the LDAP search attributes to include the users and security groups in scope for Google Cloud. What should you do next to complete this solution?

  • A1. Configure the option to suspend domain users not found in LDAP. 2. Set up a recurring GCDS task. (correct answer)
  • B1. Configure the option to delete domain users not found in LDAP. 2. Run GCDS after user and group lifecycle changes.
  • C1. Configure the LDAP search attributes to exclude manually created Cloud Identity users not found in LDAP. 2. Set up a recurring GCDS task.
  • D1. Configure the LDAP search attributes to exclude manually created Cloud Identity users not found in LDAP. 2. Run GCDS after user and group lifecycle changes.
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: 1. Configure the option to suspend domain users not found in LDAP. 2. Set up a recurring GCDS task.

Topic 1 Β· Question 113

You are troubleshooting access denied errors between Compute Engine instances connected to a Shared VPC and BigQuery datasets. The datasets reside in a project protected by a VPC Service Controls perimeter. What should you do?

  • AAdd the host project containing the Shared VPC to the service perimeter. (correct answer)
  • BAdd the service project where the Compute Engine instances reside to the service perimeter.
  • CCreate a service perimeter between the service project where the Compute Engine instances reside and the host project that contains the Shared VPC.
  • DCreate a perimeter bridge between the service project where the Compute Engine instances reside and the perimeter that contains the protected BigQuery datasets.
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Add the host project containing the Shared VPC to the service perimeter.

Explanation

Shared VPC centralizes network administration by sharing one VPC across multiple projects. A VPC provides a global, software-defined private network for your Google Cloud resources.

Topic 1 Β· Question 114

You recently joined the networking team supporting your company's Google Cloud implementation. You are tasked with familiarizing yourself with the firewall rules configuration and providing recommendations based on your networking and Google Cloud experience. What product should you recommend to detect firewall rules that are overlapped by attributes from other firewall rules with higher or equal priority?

  • ASecurity Command Center
  • BFirewall Rules Logging
  • CVPC Flow Logs
  • DFirewall Insights (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Firewall Insights.

Topic 1 Β· Question 115

The security operations team needs access to the security-related logs for all projects in their organization. They have the following requirements: β€’ Follow the least privilege model by having only view access to logs. β€’ Have access to Admin Activity logs. β€’ Have access to Data Access logs. β€’ Have access to Access Transparency logs. Which Identity and Access Management (IAM) role should the security operations team be granted?

  • Aroles/logging.privateLogViewer (correct answer)
  • Broles/logging.admin
  • Croles/viewer
  • Droles/logging.viewer
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: roles/logging.privateLogViewer.

Topic 1 Β· Question 116

You are exporting application logs to Cloud Storage. You encounter an error message that the log sinks don't support uniform bucket-level access policies. How should you resolve this error?

  • AChange the access control model for the bucket (correct answer)
  • BUpdate your sink with the correct bucket destination.
  • CAdd the roles/logging.logWriter Identity and Access Management (IAM) role to the bucket for the log sink identity.
  • DAdd the roles/logging.bucketWriter Identity and Access Management (IAM) role to the bucket for the log sink identity.
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Change the access control model for the bucket.

Topic 1 Β· Question 117

You plan to deploy your cloud infrastructure using a CI/CD cluster hosted on Compute Engine. You want to minimize the risk of its credentials being stolen by a third party. What should you do?

  • ACreate a dedicated Cloud Identity user account for the cluster. Use a strong self-hosted vault solution to store the user's temporary credentials.
  • BCreate a dedicated Cloud Identity user account for the cluster. Enable the constraints/iam.disableServiceAccountCreation organization policy at the project level.
  • CCreate a custom service account for the cluster. Enable the constraints/iam.disableServiceAccountKeyCreation organization policy at the project level (correct answer)
  • DCreate a custom service account for the cluster. Enable the constraints/iam.allowServiceAccountCredentialLifetimeExtension organization policy at the project level.
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Create a custom service account for the cluster. Enable the constraints/iam.disableServiceAccountKeyCreation organization policy at the project level

Explanation

A service account provides an identity for workloads to access Google Cloud APIs securely. Cloud IAM grants fine-grained, least-privilege access to Google Cloud resources. Organization Policy sets guardrails that constrain how resources can be configured across the org.

Topic 1 Β· Question 118

You need to set up two network segments: one with an untrusted subnet and the other with a trusted subnet. You want to configure a virtual appliance such as a next-generation firewall (NGFW) to inspect all traffic between the two network segments. How should you design the network to inspect the traffic?

  • A1. Set up one VPC with two subnets: one trusted and the other untrusted. 2. Configure a custom route for all traffic (0.0.0.0/0) pointed to the virtual appliance.
  • B1. Set up one VPC with two subnets: one trusted and the other untrusted. 2. Configure a custom route for all RFC1918 subnets pointed to the virtual appliance.
  • C1. Set up two VPC networks: one trusted and the other untrusted, and peer them together. 2. Configure a custom route on each network pointed to the virtual appliance.
  • D1. Set up two VPC networks: one trusted and the other untrusted. 2. Configure a virtual appliance using multiple network interfaces, with each interface connected to one of the VPC networks. (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: 1. Set up two VPC networks: one trusted and the other untrusted. 2. Configure a virtual appliance using multiple network interfaces, with each interface connected to one of the VPC networks.

Explanation

A VPC provides a global, software-defined private network for your Google Cloud resources.

Topic 1 Β· Question 119

You are a member of your company's security team. You have been asked to reduce your Linux bastion host external attack surface by removing all public IP addresses. Site Reliability Engineers (SREs) require access to the bastion host from public locations so they can access the internal VPC while off-site. How should you enable this access?

  • AImplement Cloud VPN for the region where the bastion host lives.
  • BImplement OS Login with 2-step verification for the bastion host.
  • CImplement Identity-Aware Proxy TCP forwarding for the bastion host. (correct answer)
  • DImplement Google Cloud Armor in front of the bastion host.
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Implement Identity-Aware Proxy TCP forwarding for the bastion host.

Explanation

Identity-Aware Proxy enforces per-request access control to apps without a VPN.

Topic 1 Β· Question 120

You need to enable VPC Service Controls and allow changes to perimeters in existing environments without preventing access to resources. Which VPC Service Controls mode should you use?

  • ACloud Run
  • BNative
  • CEnforced
  • DDry run (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Dry run.

Showing questions 101–120 of 356 Β· Page 6 of 18