Professional-Cloud-Security-Engineer Exam Question 86

Your organization hosts a financial services application running on Compute Engine instances for a third- party company. The third-party company's servers that will consume the application also run on Compute Engine in a separate Google Cloud organization. You need to configure a secure network connection between the Compute Engine instances. You have the following requirements:
* The network connection must be encrypted.
* The communication between servers must be over private IP addresses.
What should you do?
  • Professional-Cloud-Security-Engineer Exam Question 87

    A manager wants to start retaining security event logs for 2 years while minimizing costs. You write a filter to select the appropriate log entries.
    Where should you export the logs?
  • Professional-Cloud-Security-Engineer Exam Question 88

    Your financial services company has an audit requirement under a strict regulatory framework that requires comprehensive, immutable audit trails for all administrative and data access activity that ensures that data is kept for seven years. Your current logging is fragmented across individual projects. You need to establish a centralized, tamper-proof, long-term logging solution accessible for audits. What should you do?
  • Professional-Cloud-Security-Engineer Exam Question 89

    You are designing a new governance model for your organization's secrets that are stored in Secret Manager.
    Currently, secrets for Production and Non-Production applications are stored and accessed using service accounts. Your proposed solution must:
    Provide granular access to secrets
    Give you control over the rotation schedules for the encryption keys that wrap your secrets Maintain environment separation Provide ease of management Which approach should you take?
  • Professional-Cloud-Security-Engineer Exam Question 90

    You have stored company approved compute images in a single Google Cloud project that is used as an image repository. This project is protected with VPC Service Controls and exists in the perimeter along with other projects in your organization. This lets other projects deploy images from the image repository project.
    A team requires deploying a third-party disk image that is stored in an external Google Cloud organization.
    You need to grant read access to the disk image so that it can be deployed into the perimeter.
    What should you do?