Which service allows encrypted communication between Google Cloud services?
ACloud Armor
BVPC Service Controls
CGoogle Cloud Load Balancing
DCloud Logging
Explanation
Cloud Load Balancing provides SSL offloading for encrypted traffic; the others focus on different aspects of security or service management.
Q452
A company needs to store sensitive data but also comply with GDPR. Which Google Cloud service should they utilize for data access control?
ABigQuery
BCloud Storage
CCloud IAM
DCloud Pub/Sub
Explanation
Cloud IAM controls access to resources and is essential for compliance; the others are data storage or messaging services that do not govern access by themselves.
Q453
What happens when a firewall rule is defined but not applied to any VPC in Google Cloud?
AIt affects all VPCs automatically
BIt serves no purpose
CIt is applied to all egress traffic
DIt logs all denied connections
Explanation
An unassigned firewall rule has no effect, while others misinterpret its usage across VPCs or assumed logging capabilities.
Q454
Which service manages user identities in GCP?
ACloud Identity
BCloud Functions
CCloud SQL
DCloud Firestore
Explanation
Cloud Identity manages user identities, while others serve different purposes.
Q455
A company needs to encrypt its data in transit. What should they implement?
AVPC Peering
BTLS/SSL
CCloud Storage
DIAM Roles
Explanation
TLS/SSL provides encryption in transit, while others do not specifically address this need.
Q456
What happens when you apply a security policy to a project?
AAccess is granted to all users
BExisting policies are overridden
CNo effect on resources
DAccess is restricted to specified roles
Explanation
The security policy restricts access to roles defined.
Q457
Which service provides centralized control over permissions in Google Cloud?
ACloud IAM
BCloud Functions
CCloud Run
DCloud CDN
Explanation
Cloud IAM manages user permissions across Google Cloud, while the others serve different purposes.
Q458
A company needs to ensure data encryption at rest in Cloud Storage. What should they enable?
ACustomer-managed encryption keys
BNetwork security group
CCloud Pub/Sub
DCloud Load Balancer
Explanation
Customer-managed encryption keys provide control over data encryption, while other options don't address data encryption directly.
Q459
You are configuring a VPC firewall rule. What happens if you set the action to 'allow' and the direction to 'ingress'?
ABlocks incoming traffic
BAllows incoming traffic
CAllows all types of traffic
DBlocks all outgoing traffic
Explanation
Setting 'allow' with 'ingress' permits incoming traffic; the other options are incorrect interpretations of the settings.
Q460
Which Google Cloud service provides a unified security management platform?
AGoogle Cloud Security Command Center
BGoogle Kubernetes Engine
CBigQuery
DCloud Pub/Sub
Explanation
The Security Command Center provides a comprehensive view of security across Google Cloud resources, while the others serve different purposes.