
Google CloudProfessional Cloud Security Engineer
Domain 3Objective 2
3.2 Managing Encryption at Rest, in Transit, and in Use PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice Questions (Page 6)
Part of the Ensuring data protection domain, which accounts for 23% of the PROFESSIONAL-CLOUD-SECURITY-ENGINEER exam.
36questions here
8free pages
12concepts
23%of the exam
Questions 26–30
- 26
A customer wants to import an existing key into Cloud KMS. What is a required step for key import?
Select an answer first - 27
A company stores log files in a Cloud Storage bucket. The logs are encrypted with Google default encryption. The company has a data-retention policy that requires logs to be deleted after 90 days. The security team wants to automate this process without writing custom code. What should the security team do?
Select an answer first - 28
A company processes sensitive financial data in memory on Compute Engine instances. The data is encrypted at rest and in transit, but the security team is concerned about an attacker with root access to the host system reading the data while it is being processed. What should the security team use to protect the data during processing?
Select an answer first - 29
A company uses CMEK to encrypt a Cloud SQL instance. The security team wants to rotate the key every 90 days to comply with an internal policy. The team also needs to ensure that if a key is compromised, they can immediately prevent the Cloud SQL instance from using it. What should the security team do?
Select an answer first - 30
A company is deploying a new application that uses Cloud Pub/Sub for messaging and Cloud Functions for serverless processing. The data flowing through these services is not subject to any compliance requirements, but the company wants to ensure it is encrypted. The security team wants to minimize operational overhead. What should the security team do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Google Cloud. “PROFESSIONAL-CLOUD-SECURITY-ENGINEER” is a trademark of its owner, used for identification only.