
[Nov-2023] Dumps Practice Exam Questions Study Guide for the Professional-Cloud-Security-Engineer Exam
Professional-Cloud-Security-Engineer Dumps with Practice Exam Questions Answers
Google Professional-Cloud-Security-Engineer (PCSE) exam is an advanced-level certification exam designed to test the knowledge and skills of security engineers who work with Google Cloud Platform (GCP). The PCSE certification is one of the most sought-after certifications in the cloud computing industry, and it demonstrates a high level of expertise in securing GCP environments.
NEW QUESTION # 10
A large financial institution is moving its Big Data analytics to Google Cloud Platform. They want to have maximum control over the encryption process of data stored at rest in BigQuery.
What technique should the institution use?
- A. Use Cloud Storage as a federated Data Source.
- B. Customer-managed encryption keys (CMEK).
- C. Use a Cloud Hardware Security Module (Cloud HSM).
- D. Customer-supplied encryption keys (CSEK).
Answer: B
Explanation:
https://cloud.google.com/bigquery/docs/encryption-at-rest
NEW QUESTION # 11
You work for an organization in a regulated industry that has strict data protection requirements. The organization backs up their data in the cloud. To comply with data privacy regulations, this data can only be stored for a specific length of time and must be deleted after this specific period.
You want to automate the compliance with this regulation while minimizing storage costs. What should you do?
- A. Store the data in a BigQuery table, and set the table's expiration time.
- B. Store the data in a Cloud Storage bucket, and configure the bucket's Object Lifecycle Management feature.
- C. Store the data in a Cloud Bigtable table, and set an expiration time on the column families.
- D. Store the data in a persistent disk, and delete the disk at expiration time.
Answer: B
Explanation:
Explanation
To miminize costs, it's always GCS even though BQ comes as a close 2nd. But, since the question did not specify what kind of data it is (raw files vs tabular data), it is safe to assume GCS is the preferred option with LifeCycle enablement.
NEW QUESTION # 12
Your company has deployed an application on Compute Engine. The application is accessible by clients on port 587. You need to balance the load between the different instances running the application. The connection should be secured using TLS, and terminated by the Load Balancer.
What type of Load Balancing should you use?
- A. Network Load Balancing
- B. HTTP(S) Load Balancing
- C. TCP Proxy Load Balancing
- D. SSL Proxy Load Balancing
Answer: D
Explanation:
Explanation/Reference: https://cloud.google.com/load-balancing/docs/ssl/
NEW QUESTION # 13
In an effort for your company messaging app to comply with FIPS 140-2, a decision was made to use GCP compute and network services. The messaging app architecture includes a Managed Instance Group (MIG) that controls a cluster of Compute Engine instances. The instances use Local SSDs for data caching and UDP for instance-to-instance communications. The app development team is willing to make any changes necessary to comply with the standard Which options should you recommend to meet the requirements?
- A. Change the app instance-to-instance communications from UDP to TCP and enable BoringSSL on clients' TLS connections.
- B. Set Disk Encryption on the Instance Template used by the MIG to customer-managed key and use BoringSSL for all data transit between instances.
- C. Set Disk Encryption on the Instance Template used by the MIG to Google-managed Key and use BoringSSL library on all instance-to-instance communications.
- D. Encrypt all cache storage and VM-to-VM communication using the BoringCrypto module.
Answer: C
NEW QUESTION # 14
A customer deployed an application on Compute Engine that takes advantage of the elastic nature of cloud computing.
How can you work with Infrastructure Operations Engineers to best ensure that Windows Compute Engine VMs are up to date with all the latest OS patches?
- A. Use Deployment Manager to provision updated VMs into new serving Instance Groups (IGs).
- B. Build new base images when patches are available, and use a CI/CD pipeline to rebuild VMs, deploying incrementally.
- C. Federate a Domain Controller into Compute Engine, and roll out weekly patches via Group Policy Object.
- D. Reboot all VMs during the weekly maintenance window and allow the StartUp Script to download the latest patches from the internet.
Answer: D
NEW QUESTION # 15
A company is deploying their application on Google Cloud Platform. Company policy requires long-term data to be stored using a solution that can automatically replicate data over at least two geographic places.
Which Storage solution are they allowed to use?
- A. Cloud BigQuery
- B. Compute Engine Persistent Disk
- C. Cloud Bigtable
- D. Compute Engine SSD Disk
Answer: A
Explanation:
Explanation/Reference: https://cloud.google.com/bigquery/docs/locations
NEW QUESTION # 16
You need to provide a corporate user account in Google Cloud for each of your developers and operational staff who need direct access to GCP resources. Corporate policy requires you to maintain the user identity in a third-party identity management provider and leverage single sign-on. You learn that a significant number of users are using their corporate domain email addresses for personal Google accounts, and you need to follow Google recommended practices to convert existing unmanaged users to managed accounts.
Which two actions should you take? (Choose two.)
- A. Add users to your managed Google account and force users to change the email addresses associated with their personal accounts.
- B. Use Google Cloud Directory Sync to synchronize your local identity management system to Cloud Identity.
- C. Send an email to all of your employees and ask those users with corporate email addresses for personal Google accounts to delete the personal accounts immediately.
- D. Use the Google Admin console to view which managed users are using a personal account for their recovery email.
- E. Use the Transfer Tool for Unmanaged Users (TTUU) to find users with conflicting accounts and ask them to transfer their personal Google accounts.
Answer: C,D
Explanation:
Explanation/Reference:
NEW QUESTION # 17
You are auditing all your Google Cloud resources in the production project. You want to identity all principals who can change firewall rules.
What should you do?
- A. Reference the Security Health Analytics - Firewall Vulnerability Findings in the Security Command Center.
- B. Use Policy Analyzer lo query the permissions compute, firewalls, create of compute, firewalls. Create of compute,firewalls.delete.
- C. Use Policy Analyzer to query the permissions compute, firewalls, get of compute, firewalls, list.
- D. Use Firewall Insights to understand your firewall rules usage patterns.
Answer: B
NEW QUESTION # 18
A customer's internal security team must manage its own encryption keys for encrypting data on Cloud Storage and decides to use customer-supplied encryption keys (CSEK).
How should the team complete this task?
- A. Encrypt the object, then use the gsutil command line tool or the Google Cloud Platform Console to upload the object to Cloud Storage.
- B. Upload the encryption key to a Cloud Storage bucket, and then upload the object to the same bucket.
- C. Use the gsutil command line tool to upload the object to Cloud Storage, and specify the location of the encryption key.
- D. Generate an encryption key in the Google Cloud Platform Console, and upload an object to Cloud Storage using the specified key.
Answer: C
Explanation:
https://cloud.google.com/storage/docs/encryption/customer-supplied-keys#gsutil
NEW QUESTION # 19
A customer's internal security team must manage its own encryption keys for encrypting data on Cloud Storage and decides to use customer-supplied encryption keys (CSEK).
How should the team complete this task?
- A. Encrypt the object, then use the gsutil command line tool or the Google Cloud Platform Console to upload the object to Cloud Storage.
- B. Upload the encryption key to a Cloud Storage bucket, and then upload the object to the same bucket.
- C. Use the gsutil command line tool to upload the object to Cloud Storage, and specify the location of the encryption key.
- D. Generate an encryption key in the Google Cloud Platform Console, and upload an object to Cloud Storage using the specified key.
Answer: A
Explanation:
Reference:
https://cloud.google.com/storage/docs/encryption/customer-supplied-keys
NEW QUESTION # 20
You need to follow Google-recommended practices to leverage envelope encryption and encrypt data at the application layer.
What should you do?
- A. Generate a data encryption key (DEK) locally to encrypt the data, and generate a new key encryption key (KEK) in Cloud KMS to encrypt the DEK. Store both the encrypted data and the KEK.
- B. Generate a data encryption key (DEK) locally to encrypt the data, and generate a new key encryption key (KEK) in Cloud KMS to encrypt the DEK. Store both the encrypted data and the encrypted DEK.
- C. Generate a new data encryption key (DEK) in Cloud KMS to encrypt the data, and generate a key encryption key (KEK) locally to encrypt the key. Store both the encrypted data and the encrypted DEK.
- D. Generate a new data encryption key (DEK) in Cloud KMS to encrypt the data, and generate a key encryption key (KEK) locally to encrypt the key. Store both the encrypted data and the KEK.
Answer: B
Explanation:
https://cloud.google.com/kms/docs/envelope-encryption
NEW QUESTION # 21
Your company runs a website that will store PII on Google Cloud Platform. To comply with data privacy regulations, this data can only be stored for a specific amount of time and must be fully deleted after this specific period. Data that has not yet reached the time period should not be deleted. You want to automate the process of complying with this regulation.
What should you do?
- A. Store the data in a Cloud Storage bucket, and configure the bucket's Object Lifecycle Management feature.
- B. Store the data in a single BigQuery table and set the appropriate table expiration time.
- C. Store the data in a single Persistent Disk, and delete the disk at expiration time.
- D. Store the data in a single BigTable table and set an expiration time on the column families.
Answer: A
Explanation:
"To support common use cases like setting a Time to Live (TTL) for objects, retaining noncurrent versions of objects, or "downgrading" storage classes of objects to help manage costs, Cloud Storage offers the Object Lifecycle Management feature. This page describes the feature as well as the options available when using it. To learn how to enable Object Lifecycle Management, and for examples of lifecycle policies, see Managing Lifecycles." https://cloud.google.com/storage/docs/lifecycle
NEW QUESTION # 22
You are part of a security team that wants to ensure that a Cloud Storage bucket in Project A can only be readable from Project B.
You also want to ensure that data in the Cloud Storage bucket cannot be accessed from or copied to Cloud Storage buckets outside the network, even if the user has the correct credentials.
What should you do?
- A. Enable VPC Peering between Project A and B networks with strict firewall rules to allow communication between the networks.
- B. Enable Private Access in Project A and B networks with strict firewall rules to allow communication between the networks.
- C. Enable VPC Service Controls, create a perimeter with Project A and B, and include Cloud Storage service.
- D. Enable Domain Restricted Sharing Organization Policy and Bucket Policy Only on the Cloud Storage bucket.
Answer: D
Explanation:
https://cloud.google.com/resource-manager/docs/organization-policy/restricting-domains
NEW QUESTION # 23
An engineering team is launching a web application that will be public on the internet. The web application is hosted in multiple GCP regions and will be directed to the respective backend based on the URL request.
Your team wants to avoid exposing the application directly on the internet and wants to deny traffic from a specific list of malicious IP addresses Which solution should your team implement to meet these requirements?
- A. NAT Gateway
- B. Network Load Balancing
- C. SSL Proxy Load Balancing
- D. Cloud Armor
Answer: D
NEW QUESTION # 24
When creating a secure container image, which two items should you incorporate into the build if possible?
(Choose two.)
- A. Use public container images as a base image for the app.
- B. Package a single app as a container.
- C. Remove any unnecessary tools not needed by the app.
- D. Ensure that the app does not run as PID 1.
- E. Use many container image layers to hide sensitive information.
Answer: B,C
NEW QUESTION # 25
Your team needs to configure their Google Cloud Platform (GCP) environment so they can centralize the control over networking resources like firewall rules, subnets, and routes. They also have an on-premises environment where resources need access back to the GCP resources through a private VPN connection. The networking resources will need to be controlled by the network security team.
Which type of networking design should your team use to meet these requirements?
- A. Grant Compute Admin role to the networking team for each engineering project
- B. Cloud VPN Gateway between all engineering projects using a hub and spoke model
- C. Shared VPC Network with a host project and service projects
- D. VPC peering between all engineering projects using a hub and spoke model
Answer: C
Explanation:
Explanation/Reference: https://cloud.google.com/docs/enterprise/best-practices-for-enterprise- organizations#centralize_network_control
NEW QUESTION # 26
......
Free Google Cloud Certified Professional-Cloud-Security-Engineer Exam Question: https://www.dumpstorrent.com/Professional-Cloud-Security-Engineer-exam-dumps-torrent.html
Professional-Cloud-Security-Engineer by Google Cloud Certified Actual Free Exam Practice Test: https://drive.google.com/open?id=1P41gMaF3kmXoaAeGK7nUpN6XeBuVRAG7