Professional-Cloud-Security-Engineer Exam Question 6

You want to use the gcloud command-line tool to authenticate using a third-party single sign-on (SSO) SAML identity provider. Which options are necessary to ensure that authentication is supported by the third-party identity provider (IdP)? (Choose two.)
  • Professional-Cloud-Security-Engineer Exam Question 7

    Your company is using GSuite and has developed an application meant for internal usage on Google App Engine. You need to make sure that an external user cannot gain access to the application even when an employee's password has been compromised.
    What should you do?
  • Professional-Cloud-Security-Engineer Exam Question 8

    Your organization is using GitHub Actions as a continuous integration and delivery (Cl/CD) platform. You must enable access to Google Cloud resources from the Cl/CD pipelines in the most secure way.
    What should you do?
  • Professional-Cloud-Security-Engineer Exam Question 9

    As adoption of the Cloud Data Loss Prevention (DLP) API grows within the company, you need to optimize usage to reduce cost. DLP target data is stored in Cloud Storage and BigQuery. The location and region are identified as a suffix in the resource name.
    Which cost reduction options should you recommend?
  • Professional-Cloud-Security-Engineer Exam Question 10

    A customer's internal security team must manage its own encryption keys for encrypting data on Cloud Storage and decides to use customer-supplied encryption keys (CSEK).
    How should the team complete this task?