Professional-Cloud-Security-Engineer Exam Question 61

Your organization is using Google Cloud to develop and host its applications. Following Google- recommended practices, the team has created dedicated projects for development and production. Your development team is located in Canada and Germany. The operations team works exclusively from Germany to adhere to local laws. You need to ensure that admin access to Google Cloud APIs is restricted to these countries and environments. What should you do?
  • Professional-Cloud-Security-Engineer Exam Question 62

    You control network traffic for a folder in your Google Cloud environment. Your folder includes multiple projects and Virtual Private Cloud (VPC) networks You want to enforce on the folder level that egress connections are limited only to IP range 10.58.5.0/24 and only from the VPC network dev-vpc." You want to minimize implementation and maintenance effort What should you do?
  • Professional-Cloud-Security-Engineer Exam Question 63

    Your company is storing sensitive data in Cloud Storage. You want a key generated on-premises to be used in the encryption process.
    What should you do?
  • Professional-Cloud-Security-Engineer Exam Question 64

    Your organization is building a real-time recommendation engine using ML models that process live user activity data stored in BigQuery and Cloud Storage. Each new model developed is saved to Artifact Registry.
    This new system deploys models to Google Kubernetes Engine and uses Pub/Sub for message queues. Recent industry news has been reporting attacks exploiting ML model supply chains. You need to enhance the security in this serverless architecture, specifically against risks to the development and deployment pipeline.
    What should you do?
  • Professional-Cloud-Security-Engineer Exam Question 65

    Your Google Cloud environment has one organization node, one folder named Apps." and several projects within that folder The organizational node enforces the constraints/iam.allowedPolicyMemberDomains organization policy, which allows members from the terramearth.com organization The "Apps" folder enforces the constraints/iam.allowedPolicyMemberDomains organization policy, which allows members from the flowlogistic.com organization. It also has the inheritFromParent: false property.
    You attempt to grant access to a project in the Apps folder to the user [email protected].
    What is the result of your action and why?