Google Professional Cloud Security Engineer 1-10

表示モード
画像位置
文字位置
理解度の自動記録
STATUS FILTER

Choose confidence levels to display

Loading...
Q1Google Professional Cloud Security Engineer
Show answer
Correct answer: B. Mandate the adoption of Infrastructure as Code (IaC) and perform static analysis within the CI/CD pipeline to enforce policies.
Because manual reviews every time impose a heavy burden on development, the best approach is to define infrastructure as code (IaC) and automatically detect policy violations through static analysis within the CI/CD pipeline.Since security and compliance standards can be validated automatically before deployment, control is maintained while development speed is preserved.Inspection via Forseti or a VPC router only detects issues after the fact in production and does not provide preventive control.On the exam, remember that IaC plus in-pipeline policy checks is the correct answer as the “shift-left” approach that automates reviews and applies guardrails early.
Google Cloud documentation: Policy validation for Terraform configurations
Q2Google Professional Cloud Security Engineer
Show answer
Correct answer: C, D
Managed services such as App Engine and Cloud Functions let you set ingress firewall rules, but by default they provide no mechanism to control egress (outbound) traffic.The PCI DSS requirement demands ensuring that all outbound traffic is explicitly permitted.Compute Engine and GKE can explicitly control egress traffic with VPC firewall rules, so they can meet the requirement without adding compensating controls.On the exam, the deciding factor is that for requirements needing egress control, you choose IaaS or container platforms that let you directly control the network.
Google Cloud documentation: PCI DSS compliance on Google Cloud
Q3Google Professional Cloud Security Engineer
Show answer
Correct answer: C. Store the data in a Cloud Storage bucket and configure Object Lifecycle Management on that bucket.
Cloud Storage Object Lifecycle Management can automatically delete only objects that have passed their deadline, based on conditions such as an object’s age.Because it can automatically delete only the expired PII while retaining data that has not yet reached its deadline, it matches the requirement precisely.A BigQuery table expiration applies to the entire table, and a Persistent Disk can only be deleted at the disk level, so neither is suited to fine-grained deletion based on the age of individual data.On the exam, Cloud Storage lifecycle management is the standard correct answer for retention-period-based automatic deletion.
Google Cloud documentation: Object Lifecycle Management
Q4Google Professional Cloud Security Engineer
Show answer
Correct answer: B. Use the Cloud Data Loss Prevention (DLP) API to de-identify sensitive data before model training, and implement strict IAM policies for access control to BigQuery.
The core requirement is to prevent personal data from being used in training, and this is achieved through de-identification of the data.Cloud DLP (now Sensitive Data Protection) is a purpose-built tool that transforms sensitive elements through masking or tokenization, reducing risk while preserving usefulness.CMEK and Confidential VM are effective for encryption and runtime protection, but they are not a means of excluding personal data itself from training.Access restriction is handled by IAM.On the exam, remember that DLP / SDP is the correct answer for ensuring the privacy of the data content itself.
Google Cloud documentation: De-identifying sensitive data
Q5Google Professional Cloud Security Engineer
Show answer
Correct answer: B. Configure a Packet Mirroring policy.
Packet Mirroring replicates the full packets (including payloads) of the target VMs’ inbound and outbound traffic and sends them to inspection tools such as an IDS for detailed analysis.It broadly captures communication between VMs, between the internet and VMs, and from VMs to Google services, enabling deep network anomaly detection.VPC Flow Logs provide only a sample of flow metadata (source, destination, volume, etc.) and cannot detect payload-level anomalies.Cloud Audit Logs record administrative operations, not communication content.On the exam, Packet Mirroring is the correct answer when anomaly detection based on complete packet content is required.
Google Cloud documentation: Packet Mirroring overview
Q6Google Professional Cloud Security Engineer
Show answer
Correct answer: B. Set the reauthentication frequency of Google Cloud Session Control to 1 hour.
Setting the reauthentication frequency of Google Cloud Session Control causes the gcloud CLI refresh token to expire after the specified period, requiring users to reauthenticate periodically.Setting the frequency to the minimum of 1 hour minimizes the time window in which an attacker can exploit an open session.Option A’s session control for Google services targets web sessions such as Gmail and does not control reauthentication for Google Cloud / gcloud.C and D are constraints related to service account credentials and are unrelated to interactive CLI sessions.On the exam, it is important to distinguish the scope of the two.
Google Cloud documentation: Best practices for mitigating compromised OAuth tokens for gcloud CLI
Q7Google Professional Cloud Security Engineer
Show answer
Correct answer: B. Use the undelete command to restore the deleted service account.
If it is within 30 days of deletion, gcloud iam service-accounts undelete can restore the service account while preserving its original unique ID (subject ID), so existing permissions and references remain valid.Recreating with the same name changes the internal unique ID, so the previous IAM bindings are not restored and it will not work as expected.Disabling authentication compromises security, and reusing another account violates least privilege.On the exam, remember that restoration is the first choice for a recently deleted service account, and recreating with the same name does not recover its identity.
Google Cloud documentation: Deleting and undeleting service accounts
Q8Google Professional Cloud Security Engineer
Show answer
Correct answer: A. A Shared VPC network consisting of a host project and service projects.
With Shared VPC, the host project centrally manages subnets, firewall rules, and routes, and multiple service projects use that common network.By having the network security team manage the host project, you achieve both centralized network control and separation of duties at the same time.VPC peering only connects networks and cannot provide centralized management, and granting the Compute Admin role per project disperses permissions and weakens control.On-premises can connect via a VPN on the host project side.On the exam, centralization of network management equals Shared VPC as the standard correct answer.
Google Cloud documentation: Shared VPC
Q9Google Professional Cloud Security Engineer
Show answer
Correct answer: C. Create a custom service account for the cluster. Enable the organization policy constraints/iam.disableServiceAccountKeyCreation at the project level.
The best practice for workloads on Compute Engine is to attach a dedicated custom service account—rather than a user account—for authentication.By prohibiting the creation of service account keys (long-lived static credentials) with the disableServiceAccountKeyCreation constraint, the key files that would be the target of theft cease to exist.A service account attached to a VM automatically obtains short-lived tokens, so there is no need to distribute or store keys.Vault storage or the user account approach leaves the risk of leaking long-lived credentials.On the exam, prohibiting key creation is the standard means of reducing leakage risk.
Google Cloud documentation: Restricting service accounts with organization policies
Q10Google Professional Cloud Security Engineer
Show answer
Correct answer: B. Create a general-purpose service account “g-sa” to orchestrate the batch jobs. Create one service account “b-sa-[1-5]” per batch job and grant each only the permissions its job needs. Grant g-sa the Service Account Token Creator role, use g-sa to obtain short-lived access tokens for b-sa-[1-5], and run each batch job with the respective b-sa’s permissions.
By preparing a dedicated service account (b-sa-[1-5]) for each job and granting each only the permissions it needs, you thoroughly enforce least privilege.Because g-sa is granted the Service Account Token Creator role to impersonate the service accounts and each job runs with short-lived access tokens, no long-lived keys are handled at all.An approach like Option D that generates and stores keys introduces new key leakage risk.Workload identity federation is mainly intended for federation from external IdPs.On the exam, for job isolation within GCP, “dedicated SA plus impersonation plus short-lived tokens” is the correct answer.
Google Cloud documentation: Creating short-lived credentials (impersonation)