Professional-Cloud-Security-Engineer Exam Question 66

You are a member of the security team at an organization. Your team has a single GCP project with credit card payment processing systems alongside web applications and data processing systems. You want to reduce the scope of systems subject to PCI audit standards.
What should you do?
  • Professional-Cloud-Security-Engineer Exam Question 67

    Which international compliance standard provides guidelines for information security controls applicable to the provision and use of cloud services?
  • Professional-Cloud-Security-Engineer Exam Question 68

    You are designing a new governance model for your organization's secrets that are stored in Secret Manager. Currently, secrets for Production and Non-Production applications are stored and accessed using service accounts. Your proposed solution must:
    Provide granular access to secrets
    Give you control over the rotation schedules for the encryption keys that wrap your secrets Maintain environment separation Provide ease of management Which approach should you take?
  • Professional-Cloud-Security-Engineer Exam Question 69

    A company has been running their application on Compute Engine. A bug in the application allowed a malicious user to repeatedly execute a script that results in the Compute Engine instance crashing. Although the bug has been fixed, you want to get notified in case this hack re-occurs.
    What should you do?
  • Professional-Cloud-Security-Engineer Exam Question 70

    A company is deploying their application on Google Cloud Platform. Company policy requires long-term data to be stored using a solution that can automatically replicate data over at least two geographic places.
    Which Storage solution are they allowed to use?