IT認証試験問題集
毎月、GOWUKAKUは1500人以上の受験者が試験準備を助けて、試験に合格するために受験者にご協力します
 ホームページ / Professional Cloud Security Engineer 問題集  / Professional Cloud Security Engineer 問題練習

Google Professional Cloud Security Engineer 問題練習

Google Cloud Certified - Professional Cloud Security Engineer 試験

最新更新時間: 2024/04/08,合計50問。

【2024桜まつりキャンペーン】:Professional Cloud Security Engineer 最新真題を買う時、日本語版と英語版両方を同時に獲得できます。

実際の問題集を練習し、試験のポイントを了解し、テストに申し込むするかどうかを決めることができます。

さらに試験準備時間の35%を節約するには、Professional Cloud Security Engineer 問題集を使用してください。

 / 4

Question No : 1
You want to prevent users from accidentally deleting a Shared VPC host project .
Which organization-level policy constraint should you enable?

正解:
Explanation:
Reference: https://cloud.google.com/vpc/docs/provisioning-shared-vpc

Question No : 2
Your company is using Cloud Dataproc for its Spark and Hadoop jobs. You want to be able to create, rotate, and destroy symmetric encryption keys used for the persistent disks used by Cloud Dataproc. Keys can be stored in the cloud.
What should you do?

正解:

Question No : 3
How should a customer reliably deliver Stackdriver logs from GCP to their on-premises SIEM system?

正解:

Question No : 4
A customer wants to move their sensitive workloads to a Compute Engine-based cluster using Managed Instance Groups (MIGs). The jobs are bursty and must be completed quickly. They have a requirement to be able to manage and rotate the encryption keys.
Which boot disk encryption solution should you use on the cluster to meet this customer’s requirements?

正解:
Explanation:
Reference https://cloud.google.com/kubernetes-engine/docs/how-to/dynamic-provisioning-cmek

Question No : 5
A customer’s internal security team must manage its own encryption keys for encrypting data on Cloud Storage and decides to use customer-supplied encryption keys (CSEK).
How should the team complete this task?

正解:
Explanation:
Reference: https://cloud.google.com/storage/docs/encryption/customer-supplied-keys

Question No : 6
You need to follow Google-recommended practices to leverage envelope encryption and encrypt data at the application layer.
What should you do?

正解:
Explanation:
Reference: https://cloud.google.com/kms/docs/envelope-encryption

Question No : 7
You are creating an internal App Engine application that needs to access a user’s Google Drive on the user’s behalf. Your company does not want to rely on the current user’s credentials. It also wants to follow Google- recommended practices.
What should you do?

正解:
Explanation:
https://developers.google.com/admin-sdk/directory/v1/guides/delegation

Question No : 8
A customer has 300 engineers. The company wants to grant different levels of access and efficiently manage IAM permissions between users in the development and production environment projects.
Which two steps should the company take to meet these requirements? (Choose two.)

正解:

Question No : 9
As adoption of the Cloud Data Loss Prevention (DLP) API grows within the company, you need to optimize usage to reduce cost. DLP target data is stored in Cloud Storage and BigQuery. The location and region are identified as a suffix in the resource name.
Which cost reduction options should you recommend?

正解:
Explanation:
Reference: https://cloud.google.com/dlp/docs/reference/rest/v2/InspectJobConfig

Question No : 10
Your team needs to configure their Google Cloud Platform (GCP) environment so they can centralize the control over networking resources like firewall rules, subnets, and routes. They also have an on-premises environment where resources need access back to the GCP resources through a private VPN connection. The networking resources will need to be controlled by the network security team.
Which type of networking design should your team use to meet these requirements?

正解:
Explanation:
Reference: https://cloud.google.com/docs/enterprise/best-practices-for-enterprise-organizations#centralize_network_control

Question No : 11
An application running on a Compute Engine instance needs to read data from a Cloud Storage bucket. Your team does not allow Cloud Storage buckets to be globally readable and wants to ensure the principle of least privilege.
Which option meets the requirement of your team?

正解:

Question No : 12
Your company runs a website that will store PII on Google Cloud Platform. To comply with data privacy regulations, this data can only be stored for a specific amount of time and must be fully deleted after this specific period. Data that has not yet reached the time period should not be deleted. You want to automate the process of complying with this regulation.
What should you do?

正解:

Question No : 13
Your company requires the security and network engineering teams to identify all network anomalies within and across VPCs, internal traffic from VMs to VMs, traffic between end locations on the internet and VMs, and traffic between VMs to Google Cloud services in production .
Which method should you use?

正解:
Explanation:
Reference: https://cloud.google.com/architecture/best-practices-vpc-design

Question No : 14
In a shared security responsibility model for IaaS, which two layers of the stack does the customer share responsibility for? (Choose two.)

正解:

Question No : 15
Configure private access using the restricted.googleapis.com domains in on-premises DNS configurations.

正解: C

 / 4
Google