Professional-Cloud-Security-Engineer Exam Question 81

A large e-retailer is moving to Google Cloud Platform with its ecommerce website. The company wants to ensure payment information is encrypted between the customer's browser and GCP when the customers checkout online.
What should they do?
  • Professional-Cloud-Security-Engineer Exam Question 82

    Your company's detection and response team requires break-glass access to the Google Cloud organization in the event of a security investigation. At the end of each day, all security group membership is removed. You need to automate user provisioning to a Cloud Identity security group. You have created a service account to provision group memberships. Your solution must follow Google-recommended practices and comply with the principle of least privilege. What should you do?
  • Professional-Cloud-Security-Engineer Exam Question 83

    Your team needs to obtain a unified log view of all development cloud projects in your SIEM. The development projects are under the NONPROD organization folder with the test and pre-production projects.
    The development projects share the ABC-BILLING billing account with the rest of the organization.
    Which logging export strategy should you use to meet the requirements?
  • Professional-Cloud-Security-Engineer Exam Question 84

    You have created an OS image that is hardened per your organization's security standards and is being stored in a project managed by the security team. As a Google Cloud administrator, you need to make sure all VMs in your Google Cloud organization can only use that specific OS image while minimizing operational overhead. What should you do? (Choose two.)
  • Professional-Cloud-Security-Engineer Exam Question 85

    You want to make sure that your organization's Cloud Storage buckets cannot have data publicly available to the internet. You want to enforce this across all Cloud Storage buckets. What should you do?