Professional-Cloud-Security-Engineer Exam Question 66

Your company requires the security and network engineering teams to identify all network anomalies and be able to capture payloads within VPCs. Which method should you use?
  • Professional-Cloud-Security-Engineer Exam Question 67

    Your organization's Google Cloud VMs are deployed via an instance template that configures them with a public IP address in order to host web services for external users. The VMs reside in a service project that is attached to a host (VPC) project containing one custom Shared VPC for the VMs. You have been asked to reduce the exposure of the VMs to the internet while continuing to service external users. You have already recreated the instance template without a public IP address configuration to launch the managed instance group (MIG). What should you do?
  • Professional-Cloud-Security-Engineer Exam Question 68

    A database administrator notices malicious activities within their Cloud SQL instance. The database administrator wants to monitor the API calls that read the configuration or metadata of resources. Which logs should the database administrator review?
  • Professional-Cloud-Security-Engineer Exam Question 69

    A business unit at a multinational corporation signs up for GCP and starts moving workloads into GCP. The business unit creates a Cloud Identity domain with an organizational resource that has hundreds of projects.
    Your team becomes aware of this and wants to take over managing permissions and auditing the domain resources.
    Which type of access should your team grant to meet this requirement?
  • Professional-Cloud-Security-Engineer Exam Question 70

    Your security team wants to reduce the risk of user-managed keys being mismanaged and compromised. To achieve this, you need to prevent developers from creating user-managed service account keys for projects in their organization. How should you enforce this?