Professional-Cloud-Security-Engineer試験無料問題集「Google Cloud Certified - Professional Cloud Security Engineer 認定」
A company is using Google Kubernetes Engine (GKE) with container images of a mission-critical application. The company wants to scan the images for known security issues and securely share the report with the security team without exposing them outside Google Cloud.
What should you do?
What should you do?
正解:D
解答を投票する
解説: (GoShiken メンバーにのみ表示されます)
Your team creates an ingress firewall rule to allow SSH access from their corporate IP range to a specific bastion host on Compute Engine. Your team wants to make sure that this firewall rule cannot be used by unauthorized engineers who may otherwise have access to manage VMs in the development environment. What should your team do to meet this requirement?
正解:A
解答を投票する
解説: (GoShiken メンバーにのみ表示されます)
A customer implements Cloud Identity-Aware Proxy for their ERP system hosted on Compute Engine. Their security team wants to add a security layer so that the ERP systems only accept traffic from Cloud Identity-Aware Proxy.
What should the customer do to meet these requirements?
What should the customer do to meet these requirements?
正解:B
解答を投票する
解説: (GoShiken メンバーにのみ表示されます)
Your organization recently deployed a new application on Google Kubernetes Engine. You need to deploy a solution to protect the application. The solution has the following requirements:
- Scans must run at least once per week
- Must be able to detect cross-site scripting vulnerabilities
- Must be able to authenticate using Google accounts
Which solution should you use?
- Scans must run at least once per week
- Must be able to detect cross-site scripting vulnerabilities
- Must be able to authenticate using Google accounts
Which solution should you use?
正解:A
解答を投票する
解説: (GoShiken メンバーにのみ表示されます)
As adoption of the Cloud Data Loss Prevention (DLP) API grows within the company, you need to optimize usage to reduce cost. DLP target data is stored in Cloud Storage and BigQuery. The location and region are identified as a suffix in the resource name.
Which cost reduction options should you recommend?
Which cost reduction options should you recommend?
正解:A
解答を投票する
解説: (GoShiken メンバーにのみ表示されます)
An organization is starting to move its infrastructure from its on-premises environment to Google Cloud Platform (GCP). The first step the organization wants to take is to migrate its current data backup and disaster recovery solutions to GCP for later analysis. The organization's production environment will remain on-premises for an indefinite time. The organization wants a scalable and cost-efficient solution.
Which GCP solution should the organization use?
Which GCP solution should the organization use?
正解:C
解答を投票する
解説: (GoShiken メンバーにのみ表示されます)
You perform a security assessment on a customer architecture and discover that multiple VMs have public IP addresses. After providing a recommendation to remove the public IP addresses, you are told those VMs need to communicate to external sites as part of the customer's typical operations. What should you recommend to reduce the need for public IP addresses in your customer's VMs?
正解:A
解答を投票する
解説: (GoShiken メンバーにのみ表示されます)