Google Cloud

Google Cloud Certified – Professional Cloud Security Engineer

PR000224
Popular Trending

Get certified as a Professional Cloud Security Engineer with exam code PR000224 to validate your security skills in Google Cloud.

483 questions 0 views Free
Start Mock Test Timed · Full-length · Scored

Questions 331–340 of 483

Q331

Which service provides identity management for GCP resources?

  • A Cloud Identity
  • B Cloud Functions
  • C Cloud Run
  • D Cloud Pub/Sub
Explanation Cloud Identity offers user access management, while others serve different purposes.
Q332

A company needs to share cloud resources securely between projects. What should they use?

  • A VPC Network Peering
  • B IAM Roles
  • C Service Accounts
  • D Cloud Run
Explanation VPC Network Peering allows secure resource sharing, while others do not enable this type of connectivity.
Q333

You are configuring firewall rules with multiple entries. What happens when packets match multiple rules?

  • A First match is applied
  • B Last match is applied
  • C All matches are applied
  • D No match applies
Explanation In GCP, the last matching firewall rule takes precedence over earlier ones.
Q334

Which service helps you manage Google Cloud IAM roles?

  • A Cloud Identity
  • B Google Groups
  • C Cloud Key Management
  • D Cloud Asset Inventory
Explanation Cloud Identity provides IAM role management, while others either manage assets or groups.
Q335

A company needs to monitor infrastructure security vulnerabilities. Which Google Cloud service should they use?

  • A Cloud Monitoring
  • B Cloud Security Command Center
  • C Cloud Trace
  • D Identity-Aware Proxy
Explanation Cloud Security Command Center scans and identifies vulnerabilities, while others focus on monitoring or tracing requests.
Q336

You are configuring a VPC with firewall rules. What happens if an incoming request matches multiple rules?

  • A The request is blocked by default
  • B Only the first matching rule is applied
  • C All matching rules are applied
  • D The most specific rule is applied
Explanation The most specific rule takes precedence in firewall configurations, meaning the more granular rule is enforced.
Q337

Which service offers key management for encryption in Google Cloud?

  • A Cloud Key Management Service
  • B Cloud Armor
  • C Cloud Identity
  • D Compute Engine
Explanation Cloud Key Management Service centralizes encryption key management, while others serve different purposes.
Q338

A company needs to ensure that its sensitive data stored in GCS is automatically encrypted. What is the best approach?

  • A Use IAM roles for data access
  • B Turn on Object Versioning
  • C Use Google-managed encryption
  • D Implement IAM Conditions
Explanation Google-managed encryption automatically encrypts data at rest; other options do not provide encryption.
Q339

What happens when you set a 'deny all' policy in Cloud IAM?

  • A All users are blocked
  • B Only specified resources are blocked
  • C Only service accounts are blocked
  • D Only external users are blocked
Explanation 'Deny all' policies block access for all users unless excluded; others do not capture the full scope.
Q340

Which service should you use for identity management in GCP?

  • A Cloud Identity
  • B Cloud Storage
  • C Compute Engine
  • D BigQuery
Explanation Cloud Identity enables comprehensive identity management, while the others serve different purposes.