Validate that the App Engine Default Service Account is the only account that has a role that can write to BigQuery.

Validate that the App Engine Default Service Account is the only account that has a role that can write to BigQuery.View AnswerAnswer: C

March 27, 2022 No Comments READ MORE +

What should you do?

Your company is using Cloud Dataproc for its Spark and Hadoop jobs. You want to be able to create, rotate, and destroy symmetric encryption keys used for the persistent disks used by Cloud Dataproc. Keys can be stored in the cloud. What should you do?A . Use the Cloud Key...

March 26, 2022 No Comments READ MORE +

Which cryptographic token format should you use to meet these requirements?

Your company wants to determine what products they can build to help customers improve their credit scores depending on their age range. To achieve this, you need to join user information in the company's banking app with customers' credit score data received from a third party. While using this raw...

March 25, 2022 No Comments READ MORE +

What should you do?

Your company runs a website that will store PII on Google Cloud Platform. To comply with data privacy regulations, this data can only be stored for a specific amount of time and must be fully deleted after this specific period. Data that has not yet reached the time period should...

March 25, 2022 No Comments READ MORE +

Which two implied firewall rules are defined on a VPC network? (Choose two.)

Which two implied firewall rules are defined on a VPC network? (Choose two.)A . A rule that allows all outbound connectionsB . A rule that denies all inbound connectionsC . A rule that blocks all inbound port 25 connectionsD . A rule that blocks all outbound connectionsE . A rule...

March 24, 2022 No Comments READ MORE +

What solution should you propose?

You are a security engineer at a finance company. Your organization plans to store data on Google Cloud, but your leadership team is worried about the security of their highly sensitive data Specifically, your company is concerned about internal Google employees' ability to access your company's data on Google Cloud...

March 24, 2022 No Comments READ MORE +

What should you do?

You are part of a security team that wants to ensure that a Cloud Storage bucket in Project A can only be readable from Project B. You also want to ensure that data in the Cloud Storage bucket cannot be accessed from or copied to Cloud Storage buckets outside the...

March 23, 2022 No Comments READ MORE +

Which type of load balancer should you use to maintain client IP by default while using the standard network tier?

Which type of load balancer should you use to maintain client IP by default while using the standard network tier?A . SSL ProxyB . TCP ProxyC . Internal TCP/UDPD . TCP/UDP NetworkView AnswerAnswer: C Explanation: Reference: https://registry.terraform.io/providers/hashicorp/google/latest/docs/resources/compute_forw arding_rule

March 23, 2022 No Comments READ MORE +

Which type of load balancer should you use to maintain client IP by default while using the standard network tier?

Which type of load balancer should you use to maintain client IP by default while using the standard network tier?A . SSL ProxyB . TCP ProxyC . Internal TCP/UDPD . TCP/UDP NetworkView AnswerAnswer: C Explanation: Reference: https://registry.terraform.io/providers/hashicorp/google/latest/docs/resources/compute_forw arding_rule

March 23, 2022 1 Comment READ MORE +

Which solution should this customer use?

A customer needs to prevent attackers from hijacking their domain/IP and redirecting users to a malicious site through a man-in-the-middle attack. Which solution should this customer use?A . VPC Flow LogsB . Cloud ArmorC . DNS Security ExtensionsD . Cloud Identity-Aware ProxyView AnswerAnswer: C Explanation: Reference: https://cloud.google.com/blog/products/gcp/dnssec-now-available-in-cloud-dns

March 23, 2022 1 Comment READ MORE +