시험덤프
매달, 우리는 1000명 이상의 사람들이 시험 준비를 잘하고 시험을 잘 통과할 수 있도록 도와줍니다.
  / Professional Cloud Security Engineer 덤프  / Professional Cloud Security Engineer 문제 연습

Google Professional Cloud Security Engineer 시험

Google Cloud Certified - Professional Cloud Security Engineer 온라인 연습

최종 업데이트 시간: 2024년11월08일

당신은 온라인 연습 문제를 통해 Google Professional Cloud Security Engineer 시험지식에 대해 자신이 어떻게 알고 있는지 파악한 후 시험 참가 신청 여부를 결정할 수 있다.

시험을 100% 합격하고 시험 준비 시간을 35% 절약하기를 바라며 Professional Cloud Security Engineer 덤프 (최신 실제 시험 문제)를 사용 선택하여 현재 최신 50개의 시험 문제와 답을 포함하십시오.

 / 4

Question No : 1


You want to prevent users from accidentally deleting a Shared VPC host project .
Which organization-level policy constraint should you enable?

정답:
Explanation:
Reference: https://cloud.google.com/vpc/docs/provisioning-shared-vpc

Question No : 2


Your company is using Cloud Dataproc for its Spark and Hadoop jobs. You want to be able to create, rotate, and destroy symmetric encryption keys used for the persistent disks used by Cloud Dataproc. Keys can be stored in the cloud.
What should you do?

정답:

Question No : 3


How should a customer reliably deliver Stackdriver logs from GCP to their on-premises SIEM system?

정답:

Question No : 4


A customer wants to move their sensitive workloads to a Compute Engine-based cluster using Managed Instance Groups (MIGs). The jobs are bursty and must be completed quickly. They have a requirement to be able to manage and rotate the encryption keys.
Which boot disk encryption solution should you use on the cluster to meet this customer’s requirements?

정답:
Explanation:
Reference https://cloud.google.com/kubernetes-engine/docs/how-to/dynamic-provisioning-cmek

Question No : 5


A customer’s internal security team must manage its own encryption keys for encrypting data on Cloud Storage and decides to use customer-supplied encryption keys (CSEK).
How should the team complete this task?

정답:
Explanation:
Reference: https://cloud.google.com/storage/docs/encryption/customer-supplied-keys

Question No : 6


You need to follow Google-recommended practices to leverage envelope encryption and encrypt data at the application layer.
What should you do?

정답:
Explanation:
Reference: https://cloud.google.com/kms/docs/envelope-encryption

Question No : 7


You are creating an internal App Engine application that needs to access a user’s Google Drive on the user’s behalf. Your company does not want to rely on the current user’s credentials. It also wants to follow Google- recommended practices.
What should you do?

정답:
Explanation:
https://developers.google.com/admin-sdk/directory/v1/guides/delegation

Question No : 8


A customer has 300 engineers. The company wants to grant different levels of access and efficiently manage IAM permissions between users in the development and production environment projects.
Which two steps should the company take to meet these requirements? (Choose two.)

정답:

Question No : 9


As adoption of the Cloud Data Loss Prevention (DLP) API grows within the company, you need to optimize usage to reduce cost. DLP target data is stored in Cloud Storage and BigQuery. The location and region are identified as a suffix in the resource name.
Which cost reduction options should you recommend?

정답:
Explanation:
Reference: https://cloud.google.com/dlp/docs/reference/rest/v2/InspectJobConfig

Question No : 10


Your team needs to configure their Google Cloud Platform (GCP) environment so they can centralize the control over networking resources like firewall rules, subnets, and routes. They also have an on-premises environment where resources need access back to the GCP resources through a private VPN connection. The networking resources will need to be controlled by the network security team.
Which type of networking design should your team use to meet these requirements?

정답:
Explanation:
Reference: https://cloud.google.com/docs/enterprise/best-practices-for-enterprise-organizations#centralize_network_control

Question No : 11


An application running on a Compute Engine instance needs to read data from a Cloud Storage bucket. Your team does not allow Cloud Storage buckets to be globally readable and wants to ensure the principle of least privilege.
Which option meets the requirement of your team?

정답:

Question No : 12


Your company runs a website that will store PII on Google Cloud Platform. To comply with data privacy regulations, this data can only be stored for a specific amount of time and must be fully deleted after this specific period. Data that has not yet reached the time period should not be deleted. You want to automate the process of complying with this regulation.
What should you do?

정답:

Question No : 13


Your company requires the security and network engineering teams to identify all network anomalies within and across VPCs, internal traffic from VMs to VMs, traffic between end locations on the internet and VMs, and traffic between VMs to Google Cloud services in production .
Which method should you use?

정답:
Explanation:
Reference: https://cloud.google.com/architecture/best-practices-vpc-design

Question No : 14


In a shared security responsibility model for IaaS, which two layers of the stack does the customer share responsibility for? (Choose two.)

정답:

Question No : 15


Configure private access using the restricted.googleapis.com domains in on-premises DNS configurations.

정답: C

 / 4
Google