views
Pass Updated Professional-Cloud-Security-Engineer Dumps | Top Questions and Answers PDF
Sample Exam Questions and Answers ofProfessional-Cloud-Security-Engineer Dumps | 2021 Updated PDF Demo
TestInformation:
TotalQuestions: 93
TestNumber: Professional-Cloud-Security-Engineer
VendorName: Google
CertificationName: Google Cloud Certified Exam
Test Name: Google Cloud Certified - Professional Cloud Security Engineer
OfficialSite: https://www.examsforsure.com/
Question #:1
A DevOpsteam will create a new container to run on Google Kubernetes Engine. As theapplication will be internet-facing, they want to minimize the attack surfaceof the container. What should they do?
1. Use Cloud Buildto build the container images.
2. Build smallcontainers using small base images.
3. Delete non-usedversions from Container Registry.
4. Use a ContinuousDelivery tool to deploy the application.
Answer: D
Question #:2
Whilemigrating your organization’s infrastructure to GCP, a large number of userswill need to access GCP Console. The Identity Management team already has awell-established way to manage your users and want to keep using your existingActive Directory or LDAP server along with the existing SSO password. Whatshould you do?
1. Manuallysynchronize the data in Google domain with your existing Active Directory orLDAP server.
2. Use Google CloudDirectory Sync to synchronize the data in Google domain with your existingActive Directory or LDAP server.
3. Users sign indirectly to the GCP Console using the credentials from your on-premisesKerberos compliant identity provider.
4. Users sign inusing OpenID (OIDC) compatible IdP, receive an authentication token, then usethat token to log in to the GCP Console.
Answer: B
Question #:6
A websitedesign company recently migrated all customer sites to App Engine. Some sitesare still in progress and should only be visible to customers and companyemployees from any location. Which solution will restrict access to thein-progress sites?
1. Upload an.htaccess file containing the customer and employee user accounts to AppEngine.
2. Create an AppEngine firewall rule that allows access from the customer and employee networksand denies all other traffic.
3. Enable CloudIdentity-Aware Proxy (IAP), and allow access to a Google Group that containsthe customer and employee user accounts.
Use CloudVPN to create a VPN connection between the relevant on-premises networks andthe company’s GCP Virtual Private Cloud (VPC) network.
Answer: C
For More Details:
https://www.examsforsure.com/google/professional-cloud-security-engineer-dumps.html
Moreover:
https://www.examsforsure.com/google-cloud-certified-certification.html
For More Google Exams, Please visit:
https://www.examsforsure.com/Google.html
Prepared By: Examsforsure.com