Professional-Cloud-Security-Engineer Exam Question 91

Your organization is transitioning to Google Cloud You want to ensure that only trusted container images are deployed on Google Kubernetes Engine (GKE) clusters in a project. The containers must be deployed from a centrally managed. Container Registry and signed by a trusted authority.
What should you do?
Choose 2 answers
  • Professional-Cloud-Security-Engineer Exam Question 92

    Your company hosts a critical web application on Google Cloud The application is experiencing an increasing number of sophisticated layer 7 attacks, including cross-site scripting (XSS) and SQL injection attempts. You need to protect the application from these attacks while minimizing the impact on legitimate traffic and ensuring high availability. What should you do?
  • Professional-Cloud-Security-Engineer Exam Question 93

    Your company has been creating users manually in Cloud Identity to provide access to Google Cloud resources. Due to continued growth of the environment, you want to authorize the Google Cloud Directory Sync (GCDS) instance and integrate it with your on-premises LDAP server to onboard hundreds of users.
    You are required to:
    Replicate user and group lifecycle changes from the on-premises LDAP server in Cloud Identity.
    Disable any manually created users in Cloud Identity.
    You have already configured the LDAP search attributes to include the users and security groups in scope for Google Cloud. What should you do next to complete this solution?
  • Professional-Cloud-Security-Engineer Exam Question 94

    The security operations team needs access to the security-related logs for all projects in their organization.
    They have the following requirements:
    Follow the least privilege model by having only view access to logs.
    Have access to Admin Activity logs.
    Have access to Data Access logs.
    Have access to Access Transparency logs.
    Which Identity and Access Management (IAM) role should the security operations team be granted?
  • Professional-Cloud-Security-Engineer Exam Question 95

    What is the default behavior in Vertex AI regarding the use of your data for model tuning?