Professional-Cloud-Security-Engineer Exam Question 16

You are a security administrator at your company and are responsible for managing access controls (identification, authentication, and authorization) on Google Cloud. Which Google-recommended best practices should you follow when configuring authentication and authorization? (Choose two.)
  • Professional-Cloud-Security-Engineer Exam Question 17

    Your organization has implemented synchronization and SAML federation between Cloud Identity and Microsoft Active Directory. You want to reduce the risk of Google Cloud user accounts being compromised.
    What should you do?
  • Professional-Cloud-Security-Engineer Exam Question 18

    Your company's chief information security officer (CISO) is requiring business data to be stored in specific locations due to regulatory requirements that affect the company's global expansion plans. After working on a plan to implement this requirement, you determine the following:
    The services in scope are included in the Google Cloud data residency requirements.
    The business data remains within specific locations under the same organization.
    The folder structure can contain multiple data residency locations.
    The projects are aligned to specific locations.
    You plan to use the Resource Location Restriction organization policy constraint with very granular control.
    At which level in the hierarchy should you set the constraint?
  • Professional-Cloud-Security-Engineer Exam Question 19

    Your organization is using Vertex AI Workbench Instances. You must ensure that newly deployed instances are automatically kept up-to-date and that users cannot accidentally alter settings in the operating system.
    What should you do?
  • Professional-Cloud-Security-Engineer Exam Question 20

    Your security team wants to implement a defense-in-depth approach to protect sensitive data stored in a Cloud Storage bucket. Your team has the following requirements:
    The Cloud Storage bucket in Project A can only be readable from Project B.
    The Cloud Storage bucket in Project A cannot be accessed from outside the network.
    Data in the Cloud Storage bucket cannot be copied to an external Cloud Storage bucket.
    What should the security team do?