Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Google Cloud logo

Google CloudProfessional Cloud Security Engineer

Domain 2Objective 1

2.1 Designing and Configuring Perimeter Security PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice Questions (Page 4)

Part of the Securing communications and establishing boundary protection domain, which accounts for 22% of the PROFESSIONAL-CLOUD-SECURITY-ENGINEER exam.

34questions here
7free pages
10concepts
22%of the exam

Questions 16–20

  1. 16application · medium

    A company has deployed Cloud NGFW with layer 7 inspection enabled on its VPC firewall rules. The security team wants to block requests to a specific URL path (e.g., /admin) from the internet, but allow all other traffic. They also want to log blocked requests for auditing. What should the security engineer configure?

    Select an answer first
  2. 17application · medium

    A company has an internal web application hosted on a Compute Engine VM that only has a private IP address. The VM is in a VPC with no public IPs and no VPN connection. Remote employees need to access the application from their laptops using their corporate Google accounts. What should the security engineer configure to provide secure access?

    Select an answer first
  3. 18application · medium

    A company runs an internal API that is only accessible within its VPC. The API uses mutual TLS (mTLS) for authentication between services. The company wants to issue and manage the client and server certificates internally, with the ability to revoke compromised certificates quickly. What should the security engineer use?

    Select an answer first
  4. 19application · medium

    A company runs a public web application on Google Cloud behind an HTTPS load balancer. Security analysts report that attackers are sending requests with malicious SQL patterns in the URL query string and JSON payloads. The company wants to block these requests at the edge before they reach the backend, without modifying the application code. What should the security engineer configure?

    Select an answer first
  5. 20application · medium

    A company is migrating a legacy application to Google Cloud. The application currently uses public IP addresses for inter-service communication. The security team wants to minimize the attack surface by using private IP addresses for internal communication, while still allowing the application to access the internet for updates. What should the security engineer implement?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Google Cloud. “PROFESSIONAL-CLOUD-SECURITY-ENGINEER” is a trademark of its owner, used for identification only.