Professional-Cloud-Security-Engineer Exam Question 11

Your company runs a website that will store PII on Google Cloud Platform. To comply with data privacy regulations, this data can only be stored for a specific amount of time and must be fully deleted after this specific period. Data that has not yet reached the time period should not be deleted. You want to automate the process of complying with this regulation.
What should you do?
  • Professional-Cloud-Security-Engineer Exam Question 12

    You perform a security assessment on a customer architecture and discover that multiple VMs have public IP addresses. After providing a recommendation to remove the public IP addresses, you are told those VMs need to communicate to external sites as part of the customer's typical operations. What should you recommend to reduce the need for public IP addresses in your customer's VMs?
  • Professional-Cloud-Security-Engineer Exam Question 13

    Your company is storing sensitive data in Cloud Storage. You want a key generated on-premises to be used in the encryption process.
    What should you do?
  • Professional-Cloud-Security-Engineer Exam Question 14

    Which Identity-Aware Proxy role should you grant to an Identity and Access Management (IAM) user to access HTTPS resources?
  • Professional-Cloud-Security-Engineer Exam Question 15

    You are tasked with exporting and auditing security logs for login activity events for Google Cloud console and API calls that modify configurations to Google Cloud resources. Your export must meet the following requirements:
    Export related logs for all projects in the Google Cloud organization.
    Export logs in near real-time to an external SIEM.
    What should you do? (Choose two.)