Google Cloud
Google Cloud Certified – Professional Cloud Security Engineer
PR000224
Popular Trending
Get certified as a Professional Cloud Security Engineer with exam code PR000224 to validate your security skills in Google Cloud.
483 questions
0 views
Free
Questions 331–340 of 483
Which service provides identity management for GCP resources?
-
A
Cloud Identity
-
B
Cloud Functions
-
C
Cloud Run
-
D
Cloud Pub/Sub
Explanation
Cloud Identity offers user access management, while others serve different purposes.
A company needs to share cloud resources securely between projects. What should they use?
-
A
VPC Network Peering
-
B
IAM Roles
-
C
Service Accounts
-
D
Cloud Run
Explanation
VPC Network Peering allows secure resource sharing, while others do not enable this type of connectivity.
You are configuring firewall rules with multiple entries. What happens when packets match multiple rules?
-
A
First match is applied
-
B
Last match is applied
-
C
All matches are applied
-
D
No match applies
Explanation
In GCP, the last matching firewall rule takes precedence over earlier ones.
Which service helps you manage Google Cloud IAM roles?
-
A
Cloud Identity
-
B
Google Groups
-
C
Cloud Key Management
-
D
Cloud Asset Inventory
Explanation
Cloud Identity provides IAM role management, while others either manage assets or groups.
A company needs to monitor infrastructure security vulnerabilities. Which Google Cloud service should they use?
-
A
Cloud Monitoring
-
B
Cloud Security Command Center
-
C
Cloud Trace
-
D
Identity-Aware Proxy
Explanation
Cloud Security Command Center scans and identifies vulnerabilities, while others focus on monitoring or tracing requests.
You are configuring a VPC with firewall rules. What happens if an incoming request matches multiple rules?
-
A
The request is blocked by default
-
B
Only the first matching rule is applied
-
C
All matching rules are applied
-
D
The most specific rule is applied
Explanation
The most specific rule takes precedence in firewall configurations, meaning the more granular rule is enforced.
Which service offers key management for encryption in Google Cloud?
-
A
Cloud Key Management Service
-
B
Cloud Armor
-
C
Cloud Identity
-
D
Compute Engine
Explanation
Cloud Key Management Service centralizes encryption key management, while others serve different purposes.
A company needs to ensure that its sensitive data stored in GCS is automatically encrypted. What is the best approach?
-
A
Use IAM roles for data access
-
B
Turn on Object Versioning
-
C
Use Google-managed encryption
-
D
Implement IAM Conditions
Explanation
Google-managed encryption automatically encrypts data at rest; other options do not provide encryption.
What happens when you set a 'deny all' policy in Cloud IAM?
-
A
All users are blocked
-
B
Only specified resources are blocked
-
C
Only service accounts are blocked
-
D
Only external users are blocked
Explanation
'Deny all' policies block access for all users unless excluded; others do not capture the full scope.
Which service should you use for identity management in GCP?
-
A
Cloud Identity
-
B
Cloud Storage
-
C
Compute Engine
-
D
BigQuery
Explanation
Cloud Identity enables comprehensive identity management, while the others serve different purposes.