
Google CloudProfessional Cloud Security Engineer
Domain 2Objective 1
2.1 Designing and Configuring Perimeter Security PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice Questions (Page 7)
Part of the Securing communications and establishing boundary protection domain, which accounts for 22% of the PROFESSIONAL-CLOUD-SECURITY-ENGINEER exam.
34questions here
7free pages
10concepts
22%of the exam
Questions 31–34
- 31
A company runs a microservices architecture on Google Kubernetes Engine (GKE) with multiple services communicating over mTLS. The security team wants to use a private CA to issue certificates for these services, but also needs to ensure that certificates can be revoked quickly if a service is compromised. They also want to minimize the operational overhead of managing the CA. What should the security engineer do?
Select an answer first - 32
What is the purpose of enabling Cloud DNS logging?
Select an answer first - 33
A company runs a multi-region web application behind a global external load balancer. The security team wants to protect the application from DDoS attacks and also enforce a security policy that blocks requests from certain countries. They also want to ensure that health checks are not affected by the security policy. What should the security engineer configure?
Select an answer first - 34
What is the primary purpose of a Cloud Next Generation Firewall (NGFW) rule in Google Cloud?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to PROFESSIONAL-CLOUD-SECURITY-ENGINEER
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Google Cloud. “PROFESSIONAL-CLOUD-SECURITY-ENGINEER” is a trademark of its owner, used for identification only.