Professional-Cloud-Security-Engineer Exam Question 106

An organization's security and risk management teams are concerned about where their responsibility lies for certain production workloads they are running in Google Cloud Platform (GCP), and where Google's responsibility lies. They are mostly running workloads using Google Cloud's Platform-as-a-Service (PaaS) offerings, including App Engine primarily.
Which one of these areas in the technology stack would they need to focus on as their primary responsibility when using App Engine?
  • Professional-Cloud-Security-Engineer Exam Question 107

    You are deploying regulated workloads on Google Cloud. The regulation has data residency and data access requirements. It also requires that support is provided from the same geographical location as where the data resides.
    What should you do?
  • Professional-Cloud-Security-Engineer Exam Question 108

    A customer wants to move their sensitive workloads to a Compute Engine-based cluster using Managed Instance Groups (MIGs). The jobs are bursty and must be completed quickly. They have a requirement to be able to manage and rotate the encryption keys.
    Which boot disk encryption solution should you use on the cluster to meet this customer's requirements?
  • Professional-Cloud-Security-Engineer Exam Question 109

    A customer needs to prevent attackers from hijacking their domain/IP and redirecting users to a malicious site through a man-in-the-middle attack.
    Which solution should this customer use?
  • Professional-Cloud-Security-Engineer Exam Question 110

    An organization is moving applications to Google Cloud while maintaining a few mission-critical applications on-premises. The organization must transfer the data at a bandwidth of at least 50 Gbps. What should they use to ensure secure continued connectivity between sites?