Professional-Cloud-Security-Engineer Exam Question 66

When creating a secure container image, which two items should you incorporate into the build if possible? (Choose two.)
  • Professional-Cloud-Security-Engineer Exam Question 67

    Your DevOps team uses Packer to build Compute Engine images by using this process:
    1 Create an ephemeral Compute Engine VM.
    2 Copy a binary from a Cloud Storage bucket to the VM's file system.
    3 Update the VM's package manager.
    4 Install external packages from the internet onto the VM.
    Your security team just enabled the organizational policy. consrraints/compure.vnExtemallpAccess. to restrict the usage of public IP Addresses on VMs. In response your DevOps team updated their scripts to remove public IP addresses on the Compute Engine VMs however the build pipeline is failing due to connectivity issues.
    What should you do?
    Choose 2 answers
  • Professional-Cloud-Security-Engineer Exam Question 68

    Applications often require access to "secrets" - small pieces of sensitive data at build or run time. The administrator managing these secrets on GCP wants to keep a track of "who did what, where, and when?" within their GCP projects.
    Which two log streams would provide the information that the administrator is looking for? (Choose two.)
  • Professional-Cloud-Security-Engineer Exam Question 69

    A customer has an analytics workload running on Compute Engine that should have limited internet access.
    Your team created an egress firewall rule to deny (priority 1000) all traffic to the internet.
    The Compute Engine instances now need to reach out to the public repository to get security updates. What should your team do?
  • Professional-Cloud-Security-Engineer Exam Question 70

    You need to provide a corporate user account in Google Cloud for each of your developers and operational staff who need direct access to GCP resources. Corporate policy requires you to maintain the user identity in a third-party identity management provider and leverage single sign-on. You learn that a significant number of users are using their corporate domain email addresses for personal Google accounts, and you need to follow Google recommended practices to convert existing unmanaged users to managed accounts.
    Which two actions should you take? (Choose two.)