Professional Cloud Security Engineer practice questions
200 free questions with answers and explanations.
- 51.A security operations center (SOC) team needs to ingest security logs from various Google Cloud services, on-premises systems, and third-party SaaS applications into a single platform for centralized analysis and threat hunting. They require long-term retention, correlation capabilities across diverse data sources, and automated detection of advanced threats. Which Google Cloud service is best suited for this requirement?Managing operations
- 52.A retail company is expanding its online presence and needs to ensure that its public-facing web applications comply with PCI DSS requirements. Specifically, they need to regularly assess their Google Cloud environment for misconfigurations that could lead to data breaches, such as publicly exposed storage buckets or overly permissive IAM roles on critical resources. Which Security Command Center service is best suited for this continuous compliance and misconfiguration assessment?Managing operations
- 53.A security engineer needs to ensure that specific sensitive log entries, such as those indicating data exfiltration attempts or critical security alerts, are immediately forwarded to a Security Information and Event Management (SIEM) system for real-time analysis and incident response. They want to avoid any delays in log delivery and ensure reliability. Which Cloud Logging feature should be configured?Managing operations
- 54.A security operations center (SOC) team is responsible for rapidly investigating and responding to security incidents across a vast Google Cloud environment. They need to correlate security events from various sources, including Cloud Logging, Security Command Center, and third-party security tools, over extended periods to detect sophisticated, multi-stage attacks. Which Google Cloud service is designed for this advanced security analytics and threat hunting capability?Managing operations
- 55.A financial services company is migrating its critical applications to Google Cloud. They require a centralized security posture management solution that can identify misconfigurations, vulnerabilities, and threats across all their projects and folders, providing a consolidated view for security teams. The solution must also support custom security policies. Which Google Cloud service should be implemented?Managing operations
- 56.A company is using Security Command Center (SCC) Premium. They want to ensure that any new or existing Cloud Storage bucket that is publicly accessible is immediately flagged as a high-priority finding. They also need to ensure that their security team is notified via email within minutes of such a finding. How should they configure Security Command Center and Cloud Monitoring to achieve this?Managing operations
- 57.A security engineer is setting up a new Google Cloud project. They need to ensure that all firewall rules created within this project are automatically analyzed against an organizational security policy that prohibits specific egress ports (e.g., port 25). They also want to identify any existing firewall rules that violate this policy and get recommendations for remediation. Which Google Cloud service combination should they use?Managing operations
- 58.A large e-commerce company uses Google Cloud for its global operations. Their security team needs a unified view of security findings, vulnerabilities, and compliance status across all projects and folders within their organization. They also want to integrate these findings with their existing Security Information and Event Management (SIEM) system. Which Google Cloud service is best suited to provide this centralized security management and integration capability?Managing operations
- 59.A security auditor needs to verify that a Google Cloud organization's IAM policies adhere to the principle of least privilege across all projects. Specifically, they need to identify all users who have been granted the 'roles/editor' role directly on a project, rather than through a custom role with more granular permissions. Which Policy Intelligence tool is best suited for this task?Managing operations
- 60.A global e-commerce company uses Google Cloud for its infrastructure. They want to proactively monitor for suspicious activities, such as cryptocurrency mining, ransomware, and denial-of-service attacks, across their entire Google Cloud environment. They need a service that automatically analyzes logs for these specific threats and generates alerts. Which Google Cloud service should they use?Managing operations
- 61.A development team is deploying a new containerized application to Google Kubernetes Engine (GKE). They need to ensure that the container images used in their deployments are free from known vulnerabilities and meet organizational security policies *before* being deployed to production. Which Google Cloud service should they integrate into their CI/CD pipeline to achieve this?Managing operations
- 62.A security engineer is responsible for monitoring a critical production environment on Google Cloud. They need to ensure that any unusual access patterns, such as a user logging in from an unfamiliar country or an unusual number of failed login attempts, are immediately detected. Which Google Cloud service should be configured to provide real-time alerts for these types of suspicious activities?Managing operations
- 63.An organization is deploying a new containerized application on Google Kubernetes Engine (GKE). They need to monitor the runtime behavior of their containers for suspicious activities, such as unexpected process execution, binary tampering, or attempts to access sensitive files. They require a fully managed service that provides real-time threat detection within the GKE cluster. Which Google Cloud service should they enable?Managing operations
- 64.A large enterprise has a complex Google Cloud environment with hundreds of projects and multiple teams. They need to ensure that all Cloud Audit Logs (Admin Activity, Data Access, and System Event) from all projects are centrally collected, retained for 10 years, and made available for security analysis in a dedicated security project. They also want to ensure that these logs are not accidentally or maliciously deleted before their retention period. Which logging strategy should they implement?Managing operations
- 65.A security administrator needs to ensure that all administrative activities performed by privileged users within a specific Google Cloud project are immutable and retained for seven years to meet regulatory compliance requirements. They also need to ensure that these logs are not accidentally deleted or modified. Which combination of Cloud Logging features should be implemented?Managing operations
- 66.A security engineer is investigating a potential insider threat scenario where a compromised service account might be making unauthorized API calls. They need to quickly identify all API calls made by a specific service account across all projects in the organization, including calls that failed due to permission denied errors, for the past 30 days. Which Cloud Logging feature or product should the engineer primarily utilize?Managing operations
- 67.A manufacturing company uses Google Kubernetes Engine (GKE) for its production workloads. The security team needs to monitor for suspicious activities within the container runtime environment, such as execution of unauthorized binaries or attempts to modify container immutable files. Which Security Command Center capability should be enabled to detect these specific threats?Managing operations
- 68.A security auditor needs to verify that all API calls made by administrators within a Google Cloud organization are logged, immutable, and retained for a minimum of one year. They specifically need to ensure that these logs are not altered or deleted, even by project owners. Which type of Cloud Audit Log should be enabled, and what logging configuration should be applied to meet the immutability and retention requirements?Managing operations
- 69.A security analyst needs to create a custom dashboard in Cloud Monitoring to visualize specific security-related metrics, such as the number of `IAM policy changes` over time, `failed login attempts` from specific IP ranges, and `storage bucket permission changes`. They want to use a query language that allows for complex aggregations and transformations of log data for these visualizations. Which query language should the analyst use in Cloud Monitoring?Managing operations
- 70.An organization is migrating sensitive data to Google Cloud Storage. As per their internal security policy, they must ensure that all newly created Cloud Storage buckets are encrypted with Customer-Managed Encryption Keys (CMEK) by default. Any deviation from this policy should be flagged immediately. Which Google Cloud service should be configured to enforce this policy at the organization level?Managing operations
- 71.A development team is deploying a new web application to Google Kubernetes Engine (GKE). As part of their security best practices, they want to automatically scan their container images for known vulnerabilities before deployment. Which Google Cloud service can help them achieve this by integrating with their CI/CD pipeline?Managing operations
- 72.A security analyst needs to investigate a potential data exfiltration incident. They suspect that a compromised service account might have been used to access and download data from a Cloud Storage bucket. The investigation requires detailed records of every API call made by the service account, including the source IP address and the specific data accessed. Which type of Cloud Audit Log should the analyst focus on to retrieve this information?Managing operations
- 73.A security engineer needs to configure Cloud Monitoring to detect when a Google Cloud Storage (GCS) bucket's `uniformBucketLevelAccess` property is disabled. This change could indicate a potential security misconfiguration, as it would allow object-level ACLs to be used, potentially leading to unintended public access. Which MQL query should the engineer use to create an alerting policy for this specific condition?Managing operations
- 74.A security engineer needs to ensure that all administrative activities performed by project owners within a Google Cloud organization are logged and retained for a minimum of seven years to meet compliance requirements. They also need to ensure these logs cannot be accidentally or maliciously deleted before their retention period expires. Which combination of Cloud Logging features should the engineer configure?Managing operations
- 75.A gaming company uses Google Kubernetes Engine (GKE) for its online multiplayer games. They need to ensure that container images deployed to production are free of known vulnerabilities and that their GKE clusters are not running any vulnerable software. They also need to detect suspicious activities within running containers, such as reverse shell attempts or crypto-mining processes. Which two Google Cloud services, when used together, provide the most comprehensive solution for these requirements?Managing operations
- 76.A security engineer needs to configure Cloud Monitoring to alert them if any of their Google Cloud resources become non-compliant with a specific custom security standard. The custom standard checks for the presence of unencrypted Cloud Storage buckets and public IP addresses on Compute Engine instances. The alerts should be triggered when a resource transitions from compliant to non-compliant. Which service within Security Command Center should be used to define and monitor this custom standard?Managing operations
- 77.A company is implementing a new application that processes sensitive customer data. They need to ensure that any potential SQL injection vulnerabilities are identified before the application is deployed to production. Which Google Cloud service should be used to scan the web application for such vulnerabilities?Managing operations
- 78.A security team needs to monitor for unusual API calls and potential insider threats within their Google Cloud organization. They want to identify any API calls made from unexpected geographical locations or by service accounts that typically do not perform administrative actions. The solution should provide high-fidelity alerts without requiring extensive manual rule creation. Which Google Cloud service should they leverage?Managing operations
- 79.A security engineer is investigating a potential data exfiltration incident. They need to determine if any sensitive data was accessed by unauthorized parties. They specifically need to review logs of read operations on Cloud Storage buckets that contain customer data. To ensure these logs are available for forensic analysis, they must be retained for at least one year. Which type of Cloud Audit Logs should the engineer focus on, and how should they ensure its retention?Managing operations
- 80.A security team is investigating a series of unusual network connections originating from a Compute Engine instance. They need to determine if any firewall rules have been recently modified or created that could permit this suspicious outbound traffic, and by whom. Additionally, they want to understand the potential impact of these rules. Which Google Cloud service combination would be most effective for this investigation?Managing operations
- 81.A security analyst is investigating a potential compromise. They need to determine which user or service account generated a specific API key within a Google Cloud project and when it was created. The analyst has access to Cloud Logging for the project and organization. Where should the analyst look for this information?Configuring access within a cloud solution environment
- 82.A media company is building a new content delivery platform on Google Cloud. They need to issue TLS certificates for thousands of internal microservices and external-facing APIs. They require a highly available, scalable, and secure service that integrates seamlessly with Google Cloud's infrastructure, allowing them to manage the entire certificate lifecycle without operating their own certificate authority (CA) infrastructure. Which Google Cloud service should they use?Ensuring compliance
- 83.A financial services company is developing a critical trading platform on Google Cloud. Due to strict regulatory requirements (e.g., FINRA, PCI DSS), they need to ensure that detailed logs of all administrative access by Google Cloud personnel to their project data are available for audit, including the justification for access and the Google engineer's identity. Which Google Cloud service provides these specific audit logs?Ensuring compliance
- 84.A heavily regulated financial institution is building a new trading platform on Google Cloud. They need to ensure that the entire software supply chain is secured, from code commit to deployment. Specifically, they require that all container images deployed to their Google Kubernetes Engine (GKE) clusters are signed by approved internal security teams and have passed vulnerability scans before they can run. What is the most effective and compliant approach?Ensuring compliance
- 85.A multinational corporation uses Google Cloud and has complex compliance requirements spanning multiple regulatory frameworks (e.g., GDPR, HIPAA, PCI DSS). They need a unified way to understand their compliance posture, identify potential violations, and track remediation efforts across their entire Google Cloud environment. They are looking for a service that provides a central dashboard for security and compliance insights. Which Google Cloud service is best suited for this purpose?Ensuring compliance
- 86.A security engineer is designing an access control strategy for a new Google Cloud project. The project will host several microservices, each requiring distinct permissions to interact with various Google Cloud services like Cloud Storage, Cloud SQL, and Pub/Sub. The engineer wants to adhere to the principle of least privilege and ensure that each microservice only has the necessary permissions to perform its specific tasks. How should the engineer configure access for these microservices?Configuring access within a cloud solution environment
- 87.A security engineer is configuring a service account for a new application that will access a Cloud SQL instance. The application requires read-only access to a specific database within the instance. To adhere to the principle of least privilege, the engineer wants to grant the most restrictive permissions possible. Which IAM role should be assigned to the service account?Configuring access within a cloud solution environment
- 88.A software-as-a-service (SaaS) provider needs to demonstrate to its enterprise customers that even Google Cloud administrators cannot access their highly sensitive data without explicit, auditable approval. This is a critical compliance requirement for their service. They have already implemented Access Approval. Which additional Google Cloud service provides detailed, immutable logs of any actual access by Google personnel, including the justification and identity, to fulfill the audit requirements?Ensuring compliance
- 89.A developer needs to create a temporary service account for a CI/CD pipeline that will deploy a new application to a specific GKE cluster. The service account should exist only for the duration of the pipeline execution (maximum 30 minutes) and then be automatically deleted. Which Google Cloud IAM feature allows for the creation of short-lived, ephemeral credentials for this purpose?Configuring access within a cloud solution environment
- 90.A large enterprise is migrating its on-premises applications to Google Cloud. The security team needs to ensure that only approved virtual machine images are deployed across all projects, preventing the use of images that have not gone through their internal security vetting process. This requirement applies to all new deployments from development to production environments. Which Google Cloud service should they use to enforce this policy effectively?Ensuring compliance
- 91.A security team needs to audit all administrative activities performed by project owners across their organization's Google Cloud environment. Specifically, they want to track when a project owner creates or deletes a service account, or grants/revokes IAM roles to any principal. The audit logs must be retained for at least one year and be easily queryable for security investigations. Which type of audit log should the security engineer focus on, and how can they ensure long-term retention?Configuring access within a cloud solution environment
- 92.A security engineer is tasked with ensuring that all service account keys (JSON files) used by applications within a Google Cloud project are rotated quarterly. Currently, applications are using long-lived service account keys that are stored directly on compute instances. The engineer wants to automate the rotation process and eliminate the need for manual key management and distribution. How should the engineer achieve this?Configuring access within a cloud solution environment
- 93.A company is using several Google Cloud APIs (e.g., Cloud Vision API, Cloud Translation API) in their public-facing mobile application. They need to secure access to these APIs and prevent unauthorized usage, especially from unintended sources. Which method is the most appropriate and secure way to control access to these APIs for a public application?Configuring access within a cloud solution environment
- 94.A global pharmaceutical company is using Google Cloud to host its research data. They have a strict organizational policy that requires all Cloud Storage buckets to be created with a specific set of default IAM permissions, preventing public access and enforcing data residency for certain regions. They want to ensure that even if a developer forgets to apply these permissions, the bucket creation fails or is automatically corrected to meet the policy. How should they enforce this across all projects in their organization?Ensuring compliance
- 95.A financial institution is deploying a highly regulated application on Google Cloud. They need to ensure that no Google support personnel can ever access their sensitive data, even in emergency situations, without explicit, auditable approval from the financial institution. Which Google Cloud service directly addresses this specific requirement?Ensuring compliance
- 96.A global financial institution is implementing Google Cloud and needs to enforce specific resource configurations across its entire organization. They require that all new projects automatically prohibit the creation of external IP addresses on virtual machines and ensure that all Cloud Storage buckets are created with uniform bucket-level access. Which Google Cloud service should they use to define and enforce these constraints consistently?Ensuring compliance
- 97.A security auditor needs to verify that all service accounts created within a specific Google Cloud project adhere to the principle of least privilege. Specifically, they need to identify any service accounts that have been granted the 'roles/editor' role or broader permissions. Which Google Cloud IAM tool or feature should the auditor use to efficiently gather this information?Configuring access within a cloud solution environment
- 98.A security architect is designing a new application on Google Cloud that requires users to authenticate using their existing corporate Active Directory credentials without synchronizing user data to Google Cloud Identity. The solution must support multi-factor authentication (MFA) provided by the corporate identity provider and allow for fine-grained authorization within Google Cloud. Which Google Cloud service should the architect recommend to achieve this?Configuring access within a cloud solution environment
- 99.A security engineer is tasked with implementing a policy where a specific service account, `ci-cd-runner@my-project.iam.gserviceaccount.com`, should only be able to deploy resources to a GKE cluster during business hours (9 AM to 5 PM UTC) on weekdays. How can this time-based restriction be enforced?Configuring access within a cloud solution environment
- 100.A security architect needs to implement a policy that restricts the creation of any new Google Cloud Storage (GCS) buckets outside of specific regions (e.g., 'us-central1', 'us-east1') across the entire organization. They also want to ensure that all GCS buckets are created with Uniform bucket-level access enabled by default. Which Google Cloud service should be used to enforce these two requirements consistently?Ensuring compliance