
Google CloudProfessional Cloud Security Engineer
Domain 2Objective 1
2.1 Designing and Configuring Perimeter Security PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice Questions (Page 3)
Part of the Securing communications and establishing boundary protection domain, which accounts for 22% of the PROFESSIONAL-CLOUD-SECURITY-ENGINEER exam.
34questions here
7free pages
10concepts
22%of the exam
Questions 11–15
- 11
What is the primary use case for Certificate Authority Service (CAS) in Google Cloud?
Select an answer first - 12
A company has a hub-and-spoke VPC architecture with a central inspection VPC (hub) and multiple application VPCs (spokes). The security team wants to enforce a policy that blocks all inbound traffic from the internet to the spoke VPCs, except for HTTP/HTTPS traffic that must go through a load balancer in the hub. They also want to inspect the HTTP/HTTPS traffic for threats at the application layer. What should the security engineer configure?
Select an answer first - 13
A company has an internal web application that should only be accessible to employees who are members of the 'finance' Google group and who are connecting from a corporate network. The application is behind an internal load balancer. What should the security engineer configure to enforce this access policy?
Select an answer first - 14
A company is designing a new VPC with a public subnet for web servers and a private subnet for database servers. The web servers need to initiate outbound connections to the internet to download updates, but the database servers must not have any inbound or outbound internet access. The company wants to enforce this with firewall rules. What should the security engineer configure?
Select an answer first - 15
Which Google Cloud service is Cloud Armor typically associated with to protect traffic?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Google Cloud. “PROFESSIONAL-CLOUD-SECURITY-ENGINEER” is a trademark of its owner, used for identification only.