Professional Cloud Security Engineer practice questions
200 free questions with answers and explanations.
- 151.A security engineer needs to configure a service account that will be used by an external third-party application to publish messages to a specific Pub/Sub topic named `projects/my-project/topics/data-ingest`. The service account should only have the minimum necessary permissions for this task and nothing more. Which IAM role should be granted to the service account?Configuring access within a cloud solution environment
- 152.A global company uses Google Cloud and has diverse teams across different regions. They want to allow developers to create custom IAM roles for their specific projects, but only within a predefined set of permissions that the central security team has approved. The security team needs to prevent developers from creating custom roles that grant overly broad or unauthorized permissions (e.g., 'iam.serviceAccounts.keyAdmin' or 'resourcemanager.organizations.setIamPolicy'). How can the security engineer enforce this constraint on custom role creation?Configuring access within a cloud solution environment
- 153.A security auditor is performing a compliance check and needs to verify that no user in a specific Google Cloud project has been granted the `roles/owner` or `roles/editor` roles directly. Instead, all users should only have custom roles or more granular predefined roles. Which `gcloud` command can be used to list all IAM policy bindings for a project to identify violations?Configuring access within a cloud solution environment
- 154.A global enterprise is using Google Cloud and needs to ensure that all new Google Cloud projects are created with specific default IAM policies and billing accounts attached. They want to prevent project creators from bypassing these defaults. Which Google Cloud service should they use to enforce this requirement?Ensuring compliance
- 155.A security team needs to implement a policy that prevents any service account from being granted the 'roles/owner' role on any project within their Google Cloud organization. This policy must be enforced globally across all new and existing projects. Which Google Cloud IAM feature should they use to achieve this organization-wide enforcement?Configuring access within a cloud solution environment
- 156.A multinational corporation uses Google Cloud across various regions and needs to ensure that critical security and compliance notifications are always routed to the correct teams. They have different teams responsible for security incidents, legal compliance, and technical support, each requiring notifications for specific types of events. Which Google Cloud service should they configure to manage these diverse notification channels effectively?Ensuring compliance
- 157.A security engineer is designing an access control strategy for a new Google Cloud project. The project will host multiple applications, each requiring distinct permissions to various Google Cloud services (e.g., Cloud Storage, Cloud SQL, Pub/Sub). The engineer wants to ensure that permissions are highly granular and tailored to the exact needs of each application, minimizing unnecessary privileges. Which IAM best practice should the engineer prioritize?Configuring access within a cloud solution environment
- 158.A financial institution is migrating its on-premises data center to Google Cloud. They require a high-bandwidth, low-latency, and highly available private connection between their on-premises network and their Google Cloud VPC, bypassing the public internet entirely. They also need to manage multiple VLAN attachments for different environments (production, staging, development) over this connection. Which Google Cloud service combination should they use?Configuring network security
- 159.A security engineer is tasked with configuring firewall rules for a new application deployed on Google Compute Engine. The application uses a custom TCP port 8443 for its backend service and needs to be accessible only from a specific set of IP addresses belonging to the internal corporate network (192.168.10.0/24). Additionally, all outbound traffic from the application VMs should be allowed, except for traffic to known malicious IP ranges, which must be explicitly denied. Which firewall rule configuration will achieve these requirements?Configuring network security
- 160.A global company is setting up a new Google Cloud environment. They have multiple VPC networks in different regions and need to allow secure, private communication between specific services in these different VPCs without exposing any traffic to the public internet. They want to avoid full VPC network peering due to overlapping IP ranges and the complexity of managing shared routing tables. Which Google Cloud networking feature should they use?Configuring network security
- 161.A company is deploying a new web application on Google Cloud and needs to ensure that only traffic from specific trusted IP addresses can access the backend servers. They also want to restrict outbound traffic from these servers to only necessary services. How should a security engineer configure this using Google Cloud's networking services?Configuring network security
- 162.A large enterprise is migrating its on-premises applications to Google Cloud. They have a complex internal DNS infrastructure with thousands of records that need to be resolvable from their Google Cloud VPC networks without exposing them to the public internet. The enterprise also needs to manage these records centrally and ensure consistent resolution across hybrid environments. Which Google Cloud service should they use?Configuring network security
- 163.An organization uses Google Cloud and has several applications deployed across multiple regions. They want to centralize the management of all their firewall rules, identify unused or overly permissive rules, and gain insights into potential security risks. Which Google Cloud networking service is designed to provide these capabilities?Configuring network security
- 164.A development team is deploying a new microservice in a Google Kubernetes Engine (GKE) cluster that needs to consume a managed service (e.g., Cloud SQL, Cloud Memorystore) in a different Google Cloud project within the same organization. For security and compliance, all communication between the microservice and the managed service must remain entirely private, without traversing the public internet. Which Google Cloud networking feature should be implemented to achieve this?Configuring network security
- 165.A security engineer is configuring a Global External HTTP(S) Load Balancer for a new web application. They need to ensure that the load balancer only accepts traffic from specific trusted IP ranges and blocks all other traffic at the edge of Google's network. Additionally, they want to implement rate-limiting to protect against potential abuse. Which Google Cloud service should be integrated with the load balancer to achieve these requirements?Configuring network security
- 166.A security team needs to monitor and analyze all inbound and outbound network traffic to and from their Compute Engine instances to detect anomalies and potential security threats. They require detailed flow information, including source/destination IP, ports, protocols, and byte counts, for forensic analysis and compliance. Which Google Cloud feature should they enable on their VPC subnets?Configuring network security
- 167.A security engineer is reviewing the firewall configuration for a critical application in Google Cloud. They notice a firewall rule with a priority of 1000 that allows all ingress TCP traffic on port 22 (SSH) from `0.0.0.0/0` to instances with a specific network tag. There's another rule with a priority of 500 that denies all ingress TCP traffic on port 22 from `0.0.0.0/0` to the same network tag. What is the effective outcome for SSH access to these instances?Configuring network security
- 168.A development team is deploying a new containerized application to Google Kubernetes Engine (GKE). The application requires strict network isolation between different microservices within the same GKE cluster, ensuring that only authorized services can communicate with each other. They also need to apply granular ingress and egress policies based on pod labels and namespaces. Which GKE networking feature should they implement?Configuring network security
- 169.A company is using Cloud DNS for their domain management and has recently migrated several services to a new Google Cloud project. They need to ensure that internal applications within their VPC can resolve hostnames for these new services, but these hostnames should not be resolvable from the public internet. Which Cloud DNS feature should be configured?Configuring network security
- 170.A security team needs to monitor and analyze all inbound and outbound network traffic to and from virtual machines in a specific VPC network for security auditing and compliance purposes. They require detailed metadata about each connection, including source/destination IP, ports, protocols, and byte counts. The solution must be scalable and integrated with Google Cloud's logging and monitoring tools. Which Google Cloud networking feature should they enable?Configuring network security
- 171.A company is deploying a critical internal application in Google Cloud that needs to be accessible only by specific internal IP addresses within their VPC network. The application must not have any external IP addresses, and its traffic should never leave the Google Cloud network. They need to distribute incoming requests across multiple backend instances for high availability and scalability. Which type of Google Cloud Load Balancer should they choose?Configuring network security
- 172.A security team needs to restrict access to a critical internal web application hosted on Google Compute Engine. The application should only be accessible from a specific subnet (10.0.1.0/24) within the same VPC network and from a designated jump host (10.0.0.5) in another subnet. No other internal or external traffic should reach the application. Which firewall rule configuration approach should be used?Configuring network security
- 173.A global e-commerce company uses Google Cloud and wants to improve the performance and availability of its web application for users worldwide. They need to cache static content closer to users and terminate SSL/TLS at the edge of Google's network. Which Google Cloud service is best suited for this requirement?Configuring network security
- 174.A security auditor needs to regularly review all firewall rules configured across an organization's Google Cloud projects, including their effective policies, potential conflicts, and unused rules. The auditor also wants to understand the network topology and identify any open ports that deviate from security baselines. Which Google Cloud service provides a centralized view and analysis capabilities for this purpose?Configuring network security
- 175.A company is deploying a new application to Google Cloud that requires secure, encrypted communication between its instances and on-premises systems over the public internet. They need to ensure that the connection is highly available and resilient to single points of failure. Which Google Cloud networking service should they use?Configuring network security
- 176.A security engineer is investigating a potential data exfiltration attempt from a Google Cloud project. They suspect that an attacker might be trying to move data from a Cloud Storage bucket to an external, unauthorized location. The project is already part of a VPC Service Controls perimeter. How can the engineer quickly determine if the suspected exfiltration attempt was blocked by the perimeter?Configuring network security
- 177.A security engineer needs to configure a Google Cloud firewall rule that allows SSH access (TCP port 22) to all Compute Engine instances tagged with 'web-server' from a specific external IP range (203.0.113.0/24). Additionally, this rule should only apply to instances within the 'production' network. Which components must be correctly specified in the firewall rule configuration?Configuring network security
- 178.A company is deploying a new web application on Google Kubernetes Engine (GKE) and requires strict ingress and egress control for its pods. Specifically, they need to restrict traffic based on IP ranges, ports, and protocols, both for communication between pods and between pods and external services. Which Google Cloud networking feature, when integrated with GKE, provides this granular control?Configuring network security
- 179.A company is deploying a highly sensitive application in Google Cloud that requires extremely low latency and high throughput for communication between its microservices, which are deployed across different VPC networks within the same Google Cloud region. Direct peering is not sufficient due to the need for granular traffic control and service-level access management. The solution must also support private IP connectivity without traversing the public internet. Which Google Cloud networking service should be used?Configuring network security
- 180.A financial institution requires a highly secure and compliant environment for its critical applications in Google Cloud. They need to ensure that their VPC network's DNS resolution for internal resources cannot be tampered with or intercepted by external entities. Specifically, they want to prevent any public DNS queries from resolving their internal domain names. Which Cloud DNS feature should they configure?Configuring network security
- 181.A security engineer needs to establish a secure and highly available connection between an on-premises data center and Google Cloud. The connection must support high bandwidth and have a service level agreement (SLA) for uptime. Which Google Cloud networking product should the engineer choose?Configuring network security
- 182.A company operates a web application that experiences frequent DDoS attacks. They need a solution that can protect their application, which is fronted by a global external HTTP(S) Load Balancer, from various web-based threats, including SQL injection, cross-site scripting (XSS), and Layer 7 DDoS attacks. Which Google Cloud service should be implemented to address these security concerns?Configuring network security
- 183.A global enterprise manages thousands of firewall rules across hundreds of projects and VPC networks in Google Cloud. The security team is struggling to identify unused or overlapping firewall rules, which impacts network performance and increases the attack surface. They need a centralized tool to analyze firewall rule effectiveness, identify misconfigurations, and optimize their security posture. Which Google Cloud service can help them achieve this?Configuring network security
- 184.A global media company uses Google Cloud to host its video streaming platform. They are experiencing performance issues for users in certain geographical regions, specifically higher latency and slower load times. They need to optimize content delivery to ensure a consistent, high-quality experience for all users worldwide. Which Google Cloud service should they implement to address this challenge?Configuring network security
- 185.A company is deploying a new highly sensitive application in Google Cloud. They require that all traffic to and from the application's Compute Engine instances is inspected by a third-party Network Virtual Appliance (NVA) for deep packet inspection and intrusion prevention. The NVA is deployed in a separate VPC network. How can they ensure all traffic from the application VPC is routed through the NVA VPC before reaching its final destination, and vice versa?Configuring network security
- 186.A company is designing a new microservices architecture on Google Cloud. They have several internal services that should only be accessible by other authorized internal services within the same VPC, without exposing them to the public internet or requiring complex firewall rules for every service-to-service communication. They also want to consume managed Google services (e.g., Cloud SQL, Cloud Storage) privately from their VPC. Which Google Cloud networking feature enables this private connectivity pattern for both internal and managed services?Configuring network security
- 187.A security engineer is tasked with preventing data exfiltration from a Google Cloud project containing highly sensitive data. The project hosts several GCE instances, Cloud Storage buckets, and BigQuery datasets. The engineer needs to ensure that these resources can only be accessed from within a defined perimeter and that data cannot be moved to unauthorized projects or external destinations. Which Google Cloud service should be configured to achieve this goal?Configuring network security
- 188.A financial institution requires strict network segmentation for its critical applications in Google Cloud. They need to isolate development, staging, and production environments from each other, ensuring that traffic cannot flow between them without explicit authorization. Additionally, each environment must have its own set of firewall rules and network configurations. Which Google Cloud networking feature is best suited for this requirement?Configuring network security
- 189.A large enterprise is migrating its internal DNS infrastructure to Google Cloud. They have a complex internal network with multiple VPCs and Shared VPCs across several projects. They need to ensure that DNS resolution for internal resources is consistent and manageable across all these environments, without requiring manual configuration on every VM or application. Which Cloud DNS feature is specifically designed to facilitate this cross-VPC internal DNS resolution?Configuring network security
- 190.A security auditor needs to verify that no unauthorized external IP addresses can initiate connections to sensitive internal Virtual Machines (VMs) in a Google Cloud VPC network. The auditor wants a comprehensive view of all incoming traffic flows that were denied by firewall rules, including source IP, destination IP, port, and protocol, for a specific period. Which Google Cloud logging feature provides this information?Configuring network security
- 191.A security auditor needs to ensure that a web application hosted on Google Cloud is protected against common web vulnerabilities, such as SQL injection and cross-site scripting (XSS), and also against volumetric DDoS attacks. The application is served via a Global External HTTP(S) Load Balancer. Which Google Cloud service should be configured to provide this comprehensive protection?Configuring network security
- 192.A company is deploying a critical, latency-sensitive application on Google Cloud that requires extremely high bandwidth and low-latency connectivity to its on-premises data center. The existing Cloud VPN solution is not meeting the performance requirements. They need to ensure that the connection is fully redundant to avoid single points of failure. Which Cloud Interconnect option, along with its configuration, should be recommended?Configuring network security
- 193.A company is migrating its on-premises database servers to Google Cloud and requires a highly available, low-latency, and secure connection. The connection must support over 10 Gbps of throughput and be completely isolated from the public internet. They also need to ensure redundancy to avoid service disruption. Which Google Cloud networking solution should they implement?Configuring network security
- 194.A global e-commerce company uses Google Cloud for its web application. They need to ensure that their customers experience low latency and high availability regardless of their geographic location. Additionally, the company wants to protect its application from DDoS attacks and common web vulnerabilities. Which combination of Google Cloud networking services should they implement?Configuring network security
- 195.A company is migrating its on-premises applications to Google Cloud. They require a highly secure and private connection between their on-premises data center and their Google Cloud VPC network, ensuring that traffic never traverses the public internet. Which Google Cloud networking product should they use?Configuring network security
- 196.A large enterprise uses Google Cloud and has implemented a strict security policy requiring all access to production environments to be reviewed and approved by a security team member before being granted. This includes access by Google Support personnel during troubleshooting. How can this requirement be met for Google Cloud resources?Configuring access within a cloud solution environment
- 197.A global enterprise uses Google Kubernetes Engine (GKE) for stateless microservices. They need to ensure that their GKE workloads can securely access other Google Cloud services (e.g., Cloud Storage, Cloud SQL) without embedding static service account keys within container images or Pods. The solution must follow the principle of least privilege and simplify credentials management. Which approach should the security engineer recommend?Configuring access within a cloud solution environment
- 198.A security engineer needs to implement a policy that prevents any user from directly assigning the `roles/owner` role to any new user or service account at the project level within the entire organization. This policy should apply to all existing and future projects. How can this be achieved most effectively?Configuring access within a cloud solution environment
- 199.A global enterprise uses Google Cloud and has several VPC networks across different regions. They want to allow secure, private communication between services in one VPC network and a managed service provided by a third party (e.g., a SaaS provider) without exposing traffic to the public internet. The third-party service is also hosted on Google Cloud. Which Google Cloud networking product should they use to achieve this?Configuring network security
- 200.A company is migrating a legacy application to Google Cloud. The application requires a fixed set of external IP addresses to be allowed through its firewall for outbound connections to specific third-party APIs. The security team wants to define these allowed external IP addresses in a reusable and manageable way, ensuring consistency across multiple firewall rules and potentially different projects. Which Google Cloud networking feature should they use?Configuring network security