
Google CloudProfessional Cloud Security Engineer
Domain 3Objective 2
3.2 Managing Encryption at Rest, in Transit, and in Use PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice Questions (Page 1)
Part of the Ensuring data protection domain, which accounts for 23% of the PROFESSIONAL-CLOUD-SECURITY-ENGINEER exam.
36questions here
8free pages
12concepts
23%of the exam
Questions 1–5
- 1
A company wants to automatically delete objects in a Cloud Storage bucket after 30 days. Which feature should they use?
Select an answer first - 2
A security engineer needs to create a new customer-managed encryption key (CMEK) for use with Cloud Storage. Which Google Cloud service is used to create and manage the key?
Select an answer first - 3
A financial services company must store customer transaction data in BigQuery. Corporate policy requires that the company control the lifecycle of the encryption keys protecting this data, including the ability to rotate and revoke them independently of Google. The company does not need to store keys outside Google Cloud. What should the security team configure?
Select an answer first - 4
What is the purpose of wrapping a key during import into Cloud KMS?
Select an answer first - 5
A customer wants to run a Compute Engine VM with Confidential Computing. What must they do when creating the VM?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Google Cloud. “PROFESSIONAL-CLOUD-SECURITY-ENGINEER” is a trademark of its owner, used for identification only.