Professional-Cloud-Security-Engineer Exam Question 51

An office manager at your small startup company is responsible for matching payments to invoices and creating billing alerts. For compliance reasons, the office manager is only permitted to have the Identity and Access Management (IAM) permissions necessary for these tasks. Which two IAM roles should the office manager have? (Choose two.)
  • Professional-Cloud-Security-Engineer Exam Question 52

    A business unit at a multinational corporation signs up for GCP and starts moving workloads into GCP. The business unit creates a Cloud Identity domain with an organizational resource that has hundreds of projects.
    Your team becomes aware of this and wants to take over managing permissions and auditing the domain resources.
    Which type of access should your team grant to meet this requirement?
  • Professional-Cloud-Security-Engineer Exam Question 53

    Your team needs to configure their Google Cloud Platform (GCP) environment so they can centralize the control over networking resources like firewall rules, subnets, and routes. They also have an on-premises environment where resources need access back to the GCP resources through a private VPN connection. The networking resources will need to be controlled by the network security team.
    Which type of networking design should your team use to meet these requirements?
  • Professional-Cloud-Security-Engineer Exam Question 54

    A customer wants to move their sensitive workloads to a Compute Engine-based cluster using Managed Instance Groups (MIGs). The jobs are bursty and must be completed quickly. They have a requirement to be able to manage and rotate the encryption keys.
    Which boot disk encryption solution should you use on the cluster to meet this customer's requirements?
  • Professional-Cloud-Security-Engineer Exam Question 55

    Your team needs to make sure that a Compute Engine instance does not have access to the internet or to any Google APIs or services.
    Which two settings must remain disabled to meet these requirements? (Choose two.)