Courseiva

CCNA Design for security and compliance Questions

65 questions · Design for security and compliance · All types, answers revealed

1
MCQhard

A healthcare organization stores Protected Health Information (PHI) in Cloud SQL. They have implemented encryption at rest using CMEK and enforce TLS for all connections. To meet HIPAA compliance, they need to ensure that PHI cannot be exfiltrated from the Cloud SQL instance even if an application is compromised. The Cloud SQL instance is accessed by Compute Engine instances in the same VPC using private IPs. The security team wants to add an additional layer of defense against data exfiltration. What should they do?

A.Deploy Cloud Armor and apply a WAF rule to block suspicious traffic to the Cloud SQL instance.
B.Use the Cloud SQL Auth proxy from all applications to enforce IAM-based authentication.
C.Configure VPC Service Controls with a service perimeter that includes the Cloud SQL instance and uses Private Service Connect.
D.Enable customer-managed encryption keys (CMEK) on the Cloud SQL instance.
AnswerC

VPC Service Controls perimeters restrict data movement across project boundaries, and Private Service Connect keeps Cloud SQL traffic on private endpoints, blocking exfiltration even if the application is compromised. This adds the required defence layer beyond CMEK and TLS.

Why this answer

VPC Service Controls with a service perimeter that includes the Cloud SQL instance and uses Private Service Connect prevents data exfiltration by creating a security boundary around the Cloud SQL instance. Even if an application is compromised, the service perimeter blocks unauthorized copying or movement of PHI outside the perimeter, and Private Service Connect ensures traffic stays within Google's network without traversing the public internet. This directly addresses the requirement for an additional layer of defense against exfiltration beyond encryption and TLS.

Exam trap

In Google PCA exams, the trap is that candidates confuse encryption (CMEK) or secure connectivity (Auth proxy) with exfiltration prevention, not realizing that VPC Service Controls is the only option that creates a data boundary to block unauthorized data movement even from compromised applications.

How to eliminate wrong answers

Option A is wrong because Cloud Armor is a web application firewall (WAF) that protects HTTP(S) load-balanced traffic, but Cloud SQL uses private IPs within a VPC and does not have a public HTTP endpoint, so Cloud Armor cannot inspect or block traffic to the Cloud SQL instance directly. Option B is wrong because the Cloud SQL Auth proxy enforces IAM-based authentication and encrypts connections, but it does not prevent data exfiltration; if an application is compromised, the proxy still allows the attacker to query and extract PHI using valid credentials. Option D is wrong because CMEK is already implemented for encryption at rest, and encryption alone does not prevent data exfiltration—it only protects data if the storage media is stolen, not if an application is compromised and actively queries the database.

2
MCQhard

The firewall rule 'allow-ssh' was not created. According to the audit log, what is the most likely reason?

A.The user is not authenticated.
B.The user has the compute.securityAdmin role but not compute.firewalls.create.
C.The user does not have the compute.firewalls.create permission.
D.The firewall rule already exists and cannot be duplicated.
AnswerC

AuthorizationInfo shows granted: false for that permission.

Why this answer

The audit log indicates the firewall rule 'allow-ssh' was not created because the user lacks the specific permission required to create firewall rules in Google Cloud. The correct permission is `compute.firewalls.create`, which is part of the `compute.securityAdmin` role but not automatically granted with it; the `compute.securityAdmin` role includes `compute.firewalls.create`, so Option B is factually incorrect. The most likely reason is that the user does not have the `compute.firewalls.create` permission, which is a prerequisite for creating firewall rules.

Exam trap

The trap here is that candidates assume the `compute.securityAdmin` role does not include `compute.firewalls.create`, when in fact it does, leading them to incorrectly select Option B.

How to eliminate wrong answers

Option A is wrong because the audit log would show an authentication failure (e.g., 'unauthenticated' or 'login failed') if the user were not authenticated, but the scenario states the rule was not created, implying the user was authenticated but lacked authorization. Option B is wrong because the `compute.securityAdmin` role actually includes the `compute.firewalls.create` permission; if the user had that role, they would have the necessary permission, so this option presents a false contradiction. Option D is wrong because the audit log would show a 'resource already exists' error (HTTP 409 Conflict) if the rule already existed, but the question states the rule was not created, not that creation was attempted and failed due to duplication.

3
MCQmedium

A financial services company runs a multi-tier application on Compute Engine. They need to restrict network access so that only the web tier can communicate with the application tier, and only the application tier can access the database tier. All VMs are in the same VPC network. What is the most secure way to implement this?

A.Use Identity-Aware Proxy (IAP) to manage network access between tiers.
B.Use VPC firewall rules with target tags to allow traffic between specific tiers.
C.Create separate VPC networks for each tier and use VPC peering.
D.Assign a unique service account to each tier and use IAM conditions to restrict traffic.
AnswerB

VPC firewall rules with target tags apply ingress rules only to VMs carrying the specified tag, so the application tier accepts traffic solely from the web tier's tag and the database tier solely from the application tier, enforcing tier isolation within one VPC network.

Why this answer

VPC firewall rules with target tags allow you to precisely control ingress and egress traffic between VM instances based on their assigned tags. By tagging web tier VMs with a tag like 'web-tier' and application tier VMs with 'app-tier', you can create a firewall rule that allows traffic from 'web-tier' to 'app-tier' on the required port (e.g., TCP 8080) and another rule allowing traffic from 'app-tier' to 'db-tier' on the database port (e.g., TCP 3306). This approach enforces the principle of least privilege within a single VPC network without introducing unnecessary complexity or breaking network isolation.

Exam trap

The trap here is that candidates often confuse IAM conditions or service accounts with network-layer access control, or they overcomplicate the solution by suggesting separate VPC networks when the simplest and most secure method within a single VPC is using firewall rules with target tags.

How to eliminate wrong answers

Option A is wrong because Identity-Aware Proxy (IAP) is designed for user-level authentication and authorization to access applications and VMs via HTTPS or SSH/RDP tunnels, not for controlling network traffic between VM tiers within a VPC. Option C is wrong because creating separate VPC networks for each tier and using VPC peering would allow all traffic between the peered networks unless additional firewall rules are applied, and it adds unnecessary complexity; the question explicitly states all VMs are in the same VPC network, making this approach less secure and more complex than using tags. Option D is wrong because service accounts and IAM conditions control API-level permissions (e.g., who can create or delete resources), not network-layer traffic between VM instances; they cannot restrict which VMs can communicate with each other over the network.

4
MCQhard

A financial services firm runs a regulated workload on Compute Engine. Auditors require that all data at rest on persistent disks be encrypted with keys the firm controls and can revoke, and that key usage be logged independently of the project's Cloud Audit Logs. The firm's security policy forbids storing key material in the same project as the workload. Which approach meets these requirements?

A.Encrypt the disks with customer-supplied encryption keys stored in a Cloud Storage bucket in the workload project.
B.Use Confidential VMs with encrypted persistent disks and rely on the hypervisor to manage disk keys.
C.Use Google-managed encryption keys and enable Data Access audit logs for Compute Engine in the workload project.
D.Create a Cloud KMS key ring in a separate security project, grant the workload's service account `roles/cloudkms.cryptoKeyEncrypterDecrypter`, and attach a customer-managed encryption key to the disks.
AnswerD

Customer-managed encryption keys stored in a dedicated security project give the firm control over rotation and revocation, and placing the key ring in a different project satisfies the separation requirement. Granting only `roles/cloudkms.cryptoKeyEncrypterDecrypter` to the workload's service account follows least privilege, and Cloud KMS key usage is logged in the key project's audit logs, independent of the workload project.

Why this answer

Customer-managed encryption keys in Cloud KMS let the firm rotate and revoke key material, and hosting the key ring in a separate security project enforces separation of duties. Cloud KMS logs key operations in the key's own project, giving auditors independent visibility that is not tied to the workload project's audit configuration.

Exam trap

The trap here is conflating Confidential VMs, which protect data in use, with customer control over data-at-rest keys, which requires Cloud KMS customer-managed encryption keys.

5
MCQmedium

A healthcare company stores patient records in Cloud Storage and BigQuery. Auditors require that cryptographic keys used to protect this data are generated and stored on hardware security modules, that key material never leaves Google's infrastructure, and that the company retains the ability to control key rotation and revocation. The security team wants the least operational overhead while meeting these requirements. Which key management approach should the architect select?

A.Google-managed encryption keys with default encryption at rest
B.Customer-supplied encryption keys (CSEK) managed in the company's own on-premises key vault
C.Client-side encryption performed by the application before writing objects to Cloud Storage
D.Customer-managed encryption keys (CMEK) backed by Cloud KMS with a Cloud HSM protection level
AnswerD

CMEK with a Cloud HSM protection level generates and stores key material inside FIPS 140-2 Level 3 validated hardware security modules, and the key never leaves Google infrastructure. The organization controls rotation schedules, IAM bindings on the key, and can disable or destroy the key to revoke access, satisfying the auditors with minimal operational burden.

Why this answer

Customer-managed encryption keys using Cloud KMS with the Cloud HSM protection level satisfy all three auditor conditions: hardware security module key generation and storage, key material confined to Google infrastructure, and customer control over rotation and revocation. CSEK and client-side encryption move key custody to the customer and add heavy operational cost, while Google-managed keys remove the customer control the auditors demanded.

Exam trap

The trap here is assuming that any customer-controlled key option satisfies the hardware security module requirement, when CSEK and client-side keys are customer-held software keys with no HSM backing.

6
MCQeasy

After executing the command, a security review reveals that the service account sa-bucket-reader can also list buckets in the project, which was not intended. What is the most likely cause?

A.The etag was incorrect, causing a concurrent modification.
B.The service account has a project-level role that includes storage.list.
C.The policy update failed due to a missing condition.
D.The service account also has bucket-level IAM roles.
AnswerB

Project-level roles like roles/storage.objectAdmin or roles/viewer include storage.buckets.list.

Why this answer

The service account sa-bucket-reader was able to list buckets in the project, which requires the storage.buckets.list permission. This permission is included in several predefined project-level roles, such as roles/storage.objectViewer or roles/storage.legacyBucketReader. If the service account was granted a project-level role that includes storage.buckets.list, it would have the unintended ability to list all buckets in the project, even if bucket-level IAM was configured to restrict access to specific buckets.

Exam trap

In Google PCA exams, the distinction between project-level and resource-level IAM roles is critical. The trap here is that candidates assume bucket-level IAM is the only way to grant bucket access, forgetting that project-level roles can also include bucket-related permissions like storage.buckets.list.

How to eliminate wrong answers

Option A is wrong because an incorrect etag would cause a concurrent modification error during an IAM policy update, but it would not grant additional permissions like storage.buckets.list; the policy would simply fail to apply. Option C is wrong because a missing condition in a policy update would not cause the service account to gain unintended permissions; conditions restrict access, so their absence might allow broader access than intended, but the question states the service account already has the ability to list buckets, implying the permission was granted via a role, not due to a missing condition. Option D is wrong because bucket-level IAM roles are more granular and would not grant the project-level storage.buckets.list permission; bucket-level roles only apply to the specific bucket they are assigned to, not to listing all buckets in the project.

7
Multi-Selecthard

A software company wants to give a third-party analytics vendor read access to a specific BigQuery dataset containing aggregated, non-sensitive sales data, without creating service account keys that the vendor must store and rotate. The security team also wants to be able to revoke access quickly and to see which vendor identities accessed the data. The vendor already uses its own identity provider that supports OpenID Connect. Which TWO approaches together meet these requirements? (Choose two.)

Select 2 answers
A.Grant the federated principal the BigQuery Data Viewer role on the specific dataset rather than at the project level
B.Configure Workload Identity Federation so the vendor's OIDC provider can exchange tokens for short-lived Google credentials
C.Create a service account with a JSON key and share the key file with the vendor through a secure channel
D.Enable VPC Service Controls on the project to prevent the vendor from copying the dataset out
E.Assign the vendor the BigQuery Admin role at the project level to simplify permission management
AnswersA, B

Granting BigQuery Data Viewer at the dataset level follows least privilege by limiting the vendor to exactly the aggregated dataset they need. Combined with workload identity federation, access can be revoked by deleting the dataset-level binding, and Data Access audit logs will record the federated principal's reads.

Why this answer

Workload Identity Federation removes the need for service account keys by exchanging the vendor's OIDC tokens for short-lived Google credentials, and dataset-level BigQuery Data Viewer grants exactly the read access required. Together they deliver keyless authentication, least-privilege access, fast revocation, and attributable audit records. Static keys and broad project roles fail the security and least-privilege requirements.

Exam trap

The trap here is reaching for a service account key as the simplest way to grant external access, when keyless federation plus a narrowly scoped dataset role is the design the scenario is asking for.

8
MCQmedium

A company stores sensitive customer data in Cloud Storage buckets. They want to ensure that access to these buckets is only allowed from within their VPC network. Which configuration should they use?

A.Bucket IAM policies with condition on service account
B.Cloud Armor WAF rules
C.Private Google Access for on-premises
D.VPC Service Controls with a service perimeter
AnswerD

VPC Service Controls perimeters restrict Cloud Storage access to authorised VPC networks, blocking requests originating outside the perimeter even with valid credentials. This directly enforces the requirement that bucket access occur only from within the company's VPC network, mitigating data exfiltration.

Why this answer

D is correct because VPC Service Controls (VPC-SC) allow you to define a service perimeter that restricts access to Google Cloud Storage (and other managed services) to only requests originating from a specified VPC network. This ensures that data exfiltration and unauthorized access from outside the VPC are blocked, even if the bucket is publicly accessible or IAM allows broader access.

Exam trap

The trap here is that candidates often confuse VPC Service Controls with Private Google Access or IAM conditions, not realizing that VPC-SC is the only option that enforces network-level boundaries for Google-managed services like Cloud Storage.

How to eliminate wrong answers

Option A is wrong because Bucket IAM policies with a condition on a service account can restrict which service account can access the bucket, but they do not limit access to only requests from within a VPC network; the request could still come from outside the VPC if the service account is used elsewhere. Option B is wrong because Cloud Armor WAF rules are designed to protect HTTP(S) load-balanced applications from web attacks, not to enforce network-level access controls for Cloud Storage buckets accessed via gRPC or REST APIs. Option C is wrong because Private Google Access for on-premises allows on-premises hosts (using private IPs) to reach Google APIs and services, but it does not restrict access to only within a VPC; it actually enables access from outside the VPC, which is the opposite of the requirement.

9
MCQhard

A healthcare organization uses Cloud Storage to store protected health information (PHI). They have a compliance requirement to ensure that all objects in the bucket are encrypted with a customer-managed key (CMK) that is rotated every 90 days. They also need to log all access to the bucket and detect anomalous access patterns. Which combination of Google Cloud services should they use?

A.Cloud Storage with default encryption, Cloud Audit Logs, and Security Command Center
B.Cloud Storage with CMEK via Cloud HSM, Cloud Audit Logs, and Cloud DLP
C.Cloud Storage with CSEK, Cloud Audit Logs, and Security Command Center
D.Cloud Storage with CMEK via Cloud KMS, Cloud Audit Logs, and Chronicle
AnswerD

CMEK via Cloud KMS supplies the customer-managed key with configurable 90-day rotation, satisfying the encryption constraint. Cloud Audit Logs capture every bucket access for compliance evidence, while Chronicle ingests those logs to detect anomalous access patterns through its security analytics. Together these three services meet each stated requirement.

Why this answer

Cloud Storage with CMEK via Cloud KMS allows the organization to use a customer-managed key that can be rotated every 90 days, meeting the compliance requirement. Cloud Audit Logs capture all access to the bucket, and Chronicle provides advanced security analytics to detect anomalous access patterns, fulfilling the logging and detection needs.

Exam trap

The trap here is confusing the key management options (CMEK vs. CSEK vs. default encryption) and the security analytics tools (Security Command Center vs. Chronicle), where candidates often pick Security Command Center for anomaly detection when Chronicle is specifically designed for log-based threat detection.

How to eliminate wrong answers

Option A is wrong because default encryption uses Google-managed keys, not a customer-managed key (CMK), and Security Command Center provides vulnerability scanning but not the specific anomalous access pattern detection required. Option B is wrong because Cloud HSM is a hardware security module service for key management, but the question specifies CMEK via Cloud KMS, and Cloud DLP is for data loss prevention, not for logging or detecting anomalous access patterns. Option C is wrong because CSEK (customer-supplied encryption keys) requires the customer to manage the key material directly, which does not support automatic rotation every 90 days as needed, and Security Command Center is not designed for real-time anomalous access pattern detection like Chronicle.

10
Multi-Selecthard

An organization is implementing a data loss prevention (DLP) strategy for sensitive data stored in Cloud Storage. They want to automatically detect and redact credit card numbers in CSV files uploaded to a specific bucket. Which TWO Google Cloud services should they combine to achieve this?

Select 2 answers
A.Cloud Dataflow
B.Cloud Run
C.Cloud DLP
D.Cloud Functions
E.BigQuery
AnswersC, D

Cloud DLP supplies the infoType detectors that identify credit card numbers and the de-identification transforms that redact them. This satisfies the detection and redaction constraint, since it recognises sensitive data patterns rather than relying on filenames or metadata.

Why this answer

Cloud DLP (option C) is correct because it provides native content inspection and de-identification (redaction) of sensitive data like credit card numbers using built-in infoType detectors. Cloud Functions (option D) is correct because it can be triggered by Cloud Storage events (e.g., finalize/create) to invoke the DLP API on newly uploaded CSV files, enabling serverless, event-driven processing without managing infrastructure.

Exam trap

The trap here is that candidates may choose Cloud Dataflow (option A) thinking it is required for large-scale DLP processing, but the question specifies 'uploaded to a specific bucket' which implies per-file, event-driven processing where Cloud Functions is the simpler and correct serverless choice.

11
MCQhard

A security engineer is configuring VPC Service Controls to protect a project containing BigQuery datasets with PII. They want to prevent data exfiltration while allowing authorized users to query the data from outside the perimeter. Which configuration meets these requirements?

A.Create a perimeter that includes the project, and set the 'allowed external access' flag to true.
B.Create a perimeter and enable the 'exfiltration exception' for BigQuery.
C.Create a perimeter that includes only Compute Engine instances, and use a separate perimeter for BigQuery.
D.Create a perimeter that includes the project, and use an access level from Access Context Manager to grant access to authorized users.
AnswerD

A VPC Service Controls perimeter around the project blocks data exfiltration, while an Access Context Manager access level defines the trusted conditions under which authorised identities may reach BigQuery from outside the perimeter. Both are required to permit legitimate queries without opening the boundary.

Why this answer

VPC Service Controls use Access Context Manager (ACM) access levels to define granular, identity-based access conditions. By including the project in a perimeter and applying an access level that specifies authorized users (e.g., based on IP ranges, device state, or identity), you can allow those users to query BigQuery from outside the perimeter while blocking all other external traffic, preventing data exfiltration.

Exam trap

A common mistake in Google PCA exams is thinking VPC Service Controls have a simple 'allow external access' toggle or a dedicated 'exfiltration exception' flag, when in reality the only way to grant external access is through Access Context Manager access levels or ingress/egress rules.

How to eliminate wrong answers

Option A is wrong because VPC Service Controls do not have an 'allowed external access' flag; the correct mechanism is to use access levels from Access Context Manager to grant exceptions. Option B is wrong because there is no 'exfiltration exception' for BigQuery; VPC Service Controls block all data exfiltration by default, and exceptions are made via access levels or ingress/egress rules, not a dedicated flag. Option C is wrong because VPC Service Controls protect services like BigQuery by including the project containing the datasets, not by using separate perimeters for Compute Engine and BigQuery; Compute Engine instances are not the target resource here.

12
MCQmedium

A company runs a Kubernetes cluster on GKE. They need to ensure that pods cannot access Google Cloud APIs unless explicitly allowed through a service account. Which GKE feature should they use?

A.Network Policies
B.Pod Security Policies
C.Cloud Audit Logs
D.Workload Identity
AnswerD

Workload Identity binds a Kubernetes service account to a Google Cloud service account via IAM, so pods receive federated credentials only when explicitly mapped. This removes node-level credential inheritance, ensuring pods cannot reach Google Cloud APIs unless a binding is granted.

Why this answer

Workload Identity is the correct choice because it allows pods in GKE to authenticate to Google Cloud APIs using a specific Google service account, rather than the default Compute Engine service account. This ensures that pods cannot access any Google Cloud APIs unless explicitly granted permission via IAM roles bound to that service account, meeting the requirement for least-privilege access.

Exam trap

The trap here is that candidates often confuse network-level controls (Network Policies) with identity-based access controls, or they assume that Pod Security Policies can restrict API access, when in fact only Workload Identity provides the mechanism to explicitly bind pod identity to a specific Google service account for API authorization.

How to eliminate wrong answers

Option A is wrong because Network Policies control traffic flow between pods and external endpoints at the network layer (e.g., using IP addresses and ports), but they do not manage authentication or authorization to Google Cloud APIs. Option B is wrong because Pod Security Policies (now replaced by Pod Security Admission in GKE) enforce security constraints on pod specifications (e.g., privileged containers, host namespaces), but they do not control which Google Cloud APIs a pod can call. Option C is wrong because Cloud Audit Logs record API calls and activities for auditing purposes, but they do not restrict or prevent pods from accessing Google Cloud APIs.

13
MCQeasy

A media company runs a public web application behind a global external Application Load Balancer. They need to block traffic from specific countries subject to sanctions and rate-limit abusive clients, all without changing application code. Which Google Cloud service should the architect configure?

A.VPC firewall rules applied to the load balancer's backend instances
B.Identity-Aware Proxy with context-aware access levels based on device and location
C.Cloud Armor security policies with geographic-based rules and rate-based ban rules attached to the backend service
D.Cloud CDN with signed URLs and cache key policies
AnswerC

Cloud Armor attaches to the load balancer's backend service and evaluates requests at Google's edge. Geographic rules can deny traffic from sanctioned regions, and rate-based ban rules throttle or block clients exceeding configured thresholds, all declaratively and without application changes, matching the requirement exactly.

Why this answer

Cloud Armor security policies bind to the backend service of an external Application Load Balancer and inspect requests at Google's edge. Geographic rules deny traffic by source region, and rate-based ban rules throttle or temporarily ban clients exceeding thresholds, delivering sanctions blocking and abuse mitigation without modifying the application.

Exam trap

The trap here is assuming that VPC firewall rules, which operate on IP and port, can enforce country-based blocking or per-client HTTP rate limiting for a proxied load balancer.

14
MCQmedium

A company has a fleet of Compute Engine instances that need to access a Cloud Storage bucket. The security team requires that only instances in specific VPC networks can access the bucket, and that the data is encrypted in transit. How can this be achieved?

A.Use a Cloud Storage bucket with encryption at rest using CSEK.
B.Use Cloud Armor with IP allowlists and enable TLS for the bucket.
C.Create a VPC Service Controls perimeter with access levels, and require HTTPS for the bucket.
D.Use a Cloud Storage bucket with encryption at rest using CMEK.
AnswerC

VPC Service Controls restrict access by network, and HTTPS ensures encryption in transit.

Why this answer

VPC Service Controls allows you to define a security perimeter around Cloud Storage, restricting access to only requests originating from specific VPC networks. By configuring an access level that requires HTTPS, you enforce encryption in transit, meeting both the network restriction and data-in-transit encryption requirements.

Exam trap

In the Google PCA exam, a common trap is confusing encryption at rest (CSEK/CMEK) with encryption in transit (HTTPS/TLS), and the fact that VPC Service Controls is the only option that combines network-level access restrictions with transport encryption enforcement.

How to eliminate wrong answers

Option A is wrong because encryption at rest using CSEK (Customer-Supplied Encryption Keys) does not restrict access to specific VPC networks nor does it enforce encryption in transit; it only protects data at rest. Option B is wrong because Cloud Armor is a web application firewall for HTTP(S) load balancing, not a mechanism to restrict Cloud Storage bucket access to specific VPC networks; IP allowlists alone cannot enforce VPC-level network boundaries. Option D is wrong because encryption at rest using CMEK (Customer-Managed Encryption Keys) similarly only protects data at rest and does not provide network-level access controls or enforce encryption in transit.

15
Multi-Selectmedium

Which TWO are recommended practices for securing a Kubernetes Engine (GKE) cluster?

Select 2 answers
A.Disable HTTP load balancing to reduce attack surface.
B.Enable Binary Authorization to ensure only signed container images are deployed.
C.Use the default Compute Engine service account for all GKE nodes.
D.Use Workload Identity to bind Kubernetes service accounts to IAM service accounts.
E.Enable basic authentication for easier access management.
AnswersB, D

Binary Authorization enforces a deploy-time admission check, permitting only container images that carry a valid signature from an attested authority. Unsigned or tampered images are rejected before scheduling, preventing supply-chain compromise of the GKE cluster.

Why this answer

Option B is correct because Binary Authorization is a GKE security control that enforces deploy-time verification, allowing only container images that are attested or signed by trusted authorities to be admitted to the cluster, which prevents untrusted or tampered images from running. Option D is correct because Workload Identity is the recommended way to let GKE workloads access Google Cloud services: it binds a Kubernetes service account to an IAM service account via IAM policy bindings and the GKE metadata server, eliminating the need to export long-lived service account keys. The other options are not recommended: disabling HTTP load balancing (A) is not a standard GKE hardening practice and does not meaningfully reduce the cluster's attack surface, using the default Compute Engine service account for all nodes (C) grants overly broad, shared permissions and violates least privilege, and enabling basic authentication (E) is deprecated and insecure because it relies on static username/password credentials rather than modern identity-based access.

Exam trap

Google Cloud often tests the misconception that disabling features like HTTP load balancing is a security best practice, when in reality it breaks functionality and security should be layered (e.g., using HTTPS, IAP, or network policies) rather than removing features.

16
MCQmedium

A company is using Cloud Load Balancing to expose a web application. They want to protect against common web attacks like SQL injection and cross-site scripting. Which Google Cloud service should they configure?

A.VPC Firewall rules
B.Identity-Aware Proxy
C.Cloud Armor
D.Cloud CDN
AnswerC

Cloud Armor is Google Cloud's edge security service, providing WAF rules that filter SQL injection and cross-site scripting at the external load balancer. Attaching a security policy to the load balancer's backend service satisfies the requirement to block common web attacks.

Why this answer

Cloud Armor is the correct service because it provides Web Application Firewall (WAF) capabilities that can inspect HTTP/HTTPS traffic and filter out common web attacks such as SQL injection and cross-site scripting (XSS). It integrates directly with Cloud Load Balancing to apply pre-configured or custom rules at the edge, blocking malicious requests before they reach the backend.

Exam trap

The trap here is confusing network-layer security (VPC Firewall rules) with application-layer security (Cloud Armor), leading candidates to pick VPC Firewall rules because they sound like a general security measure.

How to eliminate wrong answers

Option A is wrong because VPC Firewall rules operate at the network layer (L3/L4) and cannot inspect application-layer payloads like HTTP requests, so they cannot detect or block SQL injection or XSS. Option B is wrong because Identity-Aware Proxy (IAP) controls access based on user identity and context, not by inspecting traffic for attack signatures; it is an authentication/authorization layer, not a WAF. Option D is wrong because Cloud CDN is a content delivery network that caches static content to improve performance and reduce latency; it does not provide any security filtering against web application attacks.

17
Multi-Selecthard

Which TWO of the following are valid methods to control access to Google Cloud resources using Identity and Access Management (IAM)?

Select 2 answers
A.Attach an IAM policy to an organization
B.Attach an IAM policy to a project
C.Attach an IAM policy to a user
D.Assign an IAM role directly to a user
E.Attach an IAM policy to a service account
AnswersA, B

IAM policies can be attached at the organisation node, and these inherit downward to all folders, projects and resources beneath it. This satisfies centralised control across the entire resource hierarchy rather than a single project scope.

Why this answer

Option A is correct because IAM policies can be attached at the organization node in the resource hierarchy, allowing centralized control over all projects, folders, and resources beneath it. Option B is correct because IAM policies can be attached to a project, which is a fundamental resource container in Google Cloud where allow policies bind principals to roles. Options C and E are incorrect because IAM policies are attached to resources (like organizations, folders, projects, and individual resources), not directly to users or service accounts; users and service accounts are principals that appear inside a policy binding.

Option D is incorrect because IAM roles are not assigned directly to a user as a standalone object; instead, a role is granted to a principal through a policy binding on a resource.

Exam trap

Google Cloud often tests the distinction between attaching a policy to a resource versus assigning a role to an identity, where candidates mistakenly think that attaching a policy to a user or service account is valid, when in fact policies are always attached to resources, not to identities.

18
MCQmedium

A financial services company runs a PCI-DSS regulated workload on Compute Engine. Auditors require that all administrative access to the VMs is brokered through a single, auditable control plane with short-lived credentials, and that no external IP addresses are assigned to the VMs. Which Google Cloud feature should the architect implement to meet these requirements?

A.Cloud Interconnect with a dedicated VLAN attachment and firewall rules restricting SSH to the corporate CIDR
B.Cloud VPN with Cloud NAT configured for outbound-only access to the VMs
C.Identity-Aware Proxy (IAP) TCP forwarding with OS Login and IAM-based SSH access
D.Shielded VM with vTPM and UEFI Secure Boot enabled on all instances
AnswerC

IAP TCP forwarding tunnels SSH over HTTPS through Google's edge, so VMs need no external IP. Combined with OS Login, IAM policies control SSH access per user or group, credentials are ephemeral, and every session is logged to Cloud Audit Logs, satisfying the auditable single control plane requirement.

Why this answer

Identity-Aware Proxy TCP forwarding tunnels SSH through Google's HTTPS edge after evaluating IAM policies, eliminating external IPs on the VMs. Paired with OS Login, it converts SSH access into IAM-governed, short-lived credentials and logs every session, giving auditors one brokered, centralized control plane with no public endpoints.

Exam trap

The trap here is assuming that private network connectivity alone (VPN, Interconnect, or NAT) satisfies an auditing requirement for identity-brokered, short-lived administrative access.

19
MCQeasy

A financial services company is migrating a sensitive customer data application to Google Cloud. The application runs on Compute Engine VMs in a VPC. The security team requires that all data at rest in Cloud Storage and BigQuery must be encrypted with customer-managed encryption keys (CMEK). Additionally, the keys must be stored in a different project than the data, and access to the keys must be audited. The operations team has set up a CMEK key in Cloud KMS in a separate project, assigned the Cloud KMS CryptoKey Encrypter/Decrypter role to the data project's Compute Engine service account, and enabled Cloud Storage and BigQuery to use CMEK. However, when the application tries to read from Cloud Storage, it fails with 'Access Denied.' The Cloud KMS key is in project 'kms-proj' and the data is in project 'data-proj'. What is the most likely cause?

A.The Compute Engine service account used by the VM does not have the Cloud KMS Decrypter role.
B.The VPC firewall rules are blocking egress to Cloud KMS.
C.The Cloud KMS key has been disabled due to an Organization Policy.
D.The Cloud Storage service agent in 'data-proj' does not have the Cloud KMS CryptoKey Encrypter/Decrypter role.
AnswerD

Cloud Storage performs CMEK envelope encryption through its per-project service agent, not the Compute Engine service account. The service agent `service-<project-number>@gs-project-accounts.iam.gserviceaccount.com` in `data-proj` requires the Cloud KMS CryptoKey Encrypter/Decrypter role on the key in `kms-proj`; without it, reads fail with Access Denied.

Why this answer

Cloud Storage uses a Google-managed service agent (not the Compute Engine service account) to interact with CMEK keys. When Cloud Storage is configured to use CMEK, its service agent in the data project must be granted the Cloud KMS CryptoKey Encrypter/Decrypter role on the key in the KMS project. Without this permission, Cloud Storage cannot decrypt the key to access the data, resulting in an 'Access Denied' error even though the VM's service account has the correct role.

Exam trap

A common trap on Google Cloud exams is the distinction between the service account used by the compute resource (e.g., Compute Engine VM) and the service agent used by the Google Cloud service (e.g., Cloud Storage), leading candidates to incorrectly assume the VM's service account handles all encryption operations.

How to eliminate wrong answers

Option A is wrong because the Compute Engine service account does not directly decrypt Cloud Storage data; Cloud Storage uses its own service agent for CMEK operations, and the VM's service account only needs the role for operations like signing URLs or accessing KMS directly, not for reading CMEK-encrypted objects. Option B is wrong because VPC firewall rules blocking egress to Cloud KMS would cause a timeout or connection error, not an 'Access Denied' response from Cloud Storage; the error is a permission issue, not a network connectivity issue. Option C is wrong because a disabled key would produce a different error (e.g., 'Key disabled' or 'CryptoKey not found'), and the question states the key was set up and assigned roles, with no indication of an Organization Policy disabling it.

20
MCQhard

A financial services company must comply with PCI DSS. They use Cloud SQL for MySQL for transaction processing. They need to ensure that all data at rest is encrypted with keys generated and stored in a Hardware Security Module (HSM) and that key rotation occurs every 90 days. Which configuration should they use?

A.Use Cloud External Key Manager (EKM) to integrate with on-premises HSM
B.Use Cloud SQL with customer-supplied encryption keys (CSEK) and automate rotation with Cloud Scheduler
C.Use Cloud SQL with CMEK backed by Cloud HSM, and set automatic rotation period of 90 days
D.Use Cloud SQL's default encryption with organization policy requiring rotation
AnswerC

CMEK with Cloud HSM provides customer-controlled, HSM-backed keys with automatic rotation.

Why this answer

Cloud SQL with CMEK backed by Cloud HSM meets the requirement for keys generated and stored in an HSM, and Cloud HSM supports automatic key rotation with a configurable period, including 90 days. CMEK allows you to manage and rotate the key used to encrypt data at rest, while Cloud HSM provides FIPS 140-2 Level 3 validated HSM for key storage. The automatic rotation period can be set to 90 days via the key rotation policy in Cloud KMS, satisfying the compliance mandate.

Exam trap

The trap here is that candidates confuse CSEK with CMEK, assuming CSEK provides HSM-backed keys, but CSEK keys are stored in Cloud KMS software, not in an HSM, and cannot be automatically rotated for Cloud SQL.

How to eliminate wrong answers

Option A is wrong because Cloud EKM integrates with an external key management system outside Google Cloud, but the requirement specifies keys generated and stored in an HSM, and EKM does not use Cloud HSM; it relies on an external partner HSM, which may not meet the 'stored in an HSM' requirement if the on-premises HSM is not Cloud HSM. Option B is wrong because Cloud SQL with CSEK uses customer-supplied encryption keys that are stored in Cloud KMS, not in an HSM, and CSEK does not support automatic rotation via Cloud Scheduler; you would need to manually re-encrypt the data, which is impractical and not supported for Cloud SQL. Option D is wrong because Cloud SQL's default encryption uses Google-managed keys, which are not generated or stored in a customer-controlled HSM, and organization policies cannot enforce key rotation on default encryption keys.

21
Multi-Selectmedium

A retail company is designing a Google Cloud landing zone for a regulated workload. They must ensure that encryption keys for Cloud Storage and BigQuery are generated and stored outside Google's infrastructure, with the ability to revoke access immediately. They also must retain detailed records of who accessed the data and when, for seven years. Which TWO configurations should the architect include? (Choose two.)

Select 2 answers
A.Use Cloud External Key Manager (Cloud EKM) with an external key manager reachable over the internet or Interconnect
B.Enable default encryption with Google-managed keys on all storage buckets
C.Configure Cloud KMS with HSM protection level for all customer-managed encryption keys
D.Enable VPC Service Controls perimeters around the storage and analytics projects
E.Enable Data Access audit logs for Cloud Storage and BigQuery and route them to a log bucket with a seven-year retention lock
AnswersA, E

Cloud EKM lets Cloud KMS call an external key manager you control, so key material resides outside Google and never enters Google's infrastructure. Revoking the external key immediately renders wrapped data keys unusable, satisfying both the external custody and rapid revocation requirements for Cloud Storage and BigQuery.

Why this answer

Cloud EKM places key custody in an external manager you operate, letting you revoke keys instantly and keeping key material outside Google, which covers the encryption requirement. Enabling Data Access audit logs and routing them into a locked, seven-year retention bucket creates the immutable access record the regulation demands.

Exam trap

The trap here is treating Cloud KMS HSM keys or VPC Service Controls as sufficient for external key custody and long-term access auditing, when neither places key material outside Google or produces the required access records.

22
Matchingmedium

Match each GCP compute service to its characteristic.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Virtual machines with full control

Managed Kubernetes clusters

Serverless containers

Platform as a Service (PaaS)

Event-driven serverless functions

Why these pairings

Compute Engine provides IaaS virtual machines; GKE offers managed Kubernetes; Cloud Run enables serverless containers; App Engine is a PaaS for web apps. Common confusions include mixing serverless and Kubernetes features.

23
MCQmedium

A company is deploying a multi-tier web application on Google Cloud. The application must comply with PCI DSS. Which combination of Google Cloud services should be used to restrict access to the database tier to only the application tier, while also encrypting data at rest and in transit?

A.Use Cloud Spanner with private IP and SSL/TLS, and enable Google-managed encryption keys
B.Use Cloud SQL with public IP and SSL/TLS, and enable Google-managed encryption keys
C.Use Cloud Datastore with secure WebSocket connections and enable customer-managed encryption keys
D.Use Cloud SQL with private IP and SSL/TLS, and enable Cloud Key Management Service (KMS) to create a key ring and customer-managed encryption key (CMEK)
AnswerD

Private IP keeps the Cloud SQL instance off the public internet, so only the application tier's VPC can reach it, while SSL/TLS encrypts data in transit and CMEK via Cloud KMS encrypts data at rest, meeting PCI DSS constraints.

Why this answer

It meets all PCI DSS requirements: Cloud SQL with private IP ensures the database tier is not exposed to the public internet, restricting access to only the application tier within the same VPC. SSL/TLS encrypts data in transit, and using Cloud KMS with a customer-managed encryption key (CMEK) provides control over encryption keys for data at rest, which is often required for compliance.

Exam trap

The trap here is that candidates often assume Google-managed encryption keys are sufficient for PCI DSS, but the standard often requires customer-managed keys (CMEK) to demonstrate control over key lifecycle, and they overlook that public IP (even with SSL) fails the network access restriction requirement.

How to eliminate wrong answers

Option A is wrong because Cloud Spanner with private IP and SSL/TLS does encrypt data in transit and restricts network access, but it uses Google-managed encryption keys by default, which may not satisfy PCI DSS requirements for customer control over encryption keys. Option B is wrong because Cloud SQL with public IP exposes the database to the internet, violating the requirement to restrict access to only the application tier, even with SSL/TLS. Option C is wrong because Cloud Datastore is a NoSQL document database that does not support secure WebSocket connections for encryption in transit (it uses gRPC/HTTP with TLS), and customer-managed encryption keys are not available for Cloud Datastore; it uses Google-managed keys only.

24
MCQmedium

A company is migrating its on-premises workloads to Google Cloud. They have strict compliance requirements that all data at rest must be encrypted with customer-managed encryption keys (CMEK). Which Google Cloud service should they use to manage the lifecycle of these keys?

A.Secret Manager
B.Cloud External Key Manager (Cloud EKM)
C.Cloud Key Management Service (Cloud KMS)
D.Cloud Hardware Security Module (Cloud HSM)
AnswerC

Cloud KMS creates, stores, rotates and controls customer-managed encryption keys, and integrates with Google Cloud services so data at rest is encrypted under CMEK. It directly satisfies the compliance requirement for managing key lifecycle rather than relying on Google-managed keys.

Why this answer

Cloud KMS is the correct service because it provides centralized management of customer-managed encryption keys (CMEK) for Google Cloud services. It allows you to create, rotate, destroy, and set permissions on symmetric and asymmetric keys, and integrates directly with services like Cloud Storage, BigQuery, and Compute Engine to enforce encryption at rest with keys you control.

Exam trap

The trap here is that candidates often confuse Cloud HSM as a key management service, but Cloud HSM is a key storage backend for Cloud KMS, not a replacement for lifecycle management; you must use Cloud KMS to control key creation, rotation, and destruction even when using HSM-backed keys.

How to eliminate wrong answers

Option A is wrong because Secret Manager is designed to store and manage secrets such as API keys, passwords, and certificates, not to manage encryption keys for data-at-rest encryption under CMEK. Option B is wrong because Cloud External Key Manager (Cloud EKM) allows you to manage keys using an external key management system outside Google Cloud, but it does not provide native lifecycle management within Google Cloud; it relies on an external partner for key operations. Option D is wrong because Cloud HSM is a hardware security module service that provides FIPS 140-2 Level 3 validated key storage and cryptographic operations, but it is an additional protection layer for keys stored in Cloud KMS, not a standalone key lifecycle management service; you still use Cloud KMS to manage the key lifecycle.

25
Multi-Selecthard

A company uses Cloud KMS to encrypt sensitive data. They need to ensure that encryption key usage is audited and that keys are rotated automatically every 30 days. Which two actions should they take? (Choose two.)

Select 2 answers
A.Enable Data Access audit logs for the Cloud KMS API
B.Create a Cloud Trigger to manually rotate the key every month
C.Enable Cloud Key Management Service's key usage monitoring
D.Use Cloud External Key Manager to rotate keys externally
E.Enable key rotation on the key by setting a rotation period of 30 days
AnswersA, E

Data Access audit logs record every encrypt/decrypt operation for compliance.

Why this answer

Enabling Data Access audit logs for the Cloud KMS API captures detailed information about every encryption key usage, including who accessed the key, when, and what operation was performed. This meets the auditing requirement by recording all key usage events in Cloud Audit Logs, which can be reviewed for compliance and security analysis.

Exam trap

The trap here is that candidates often confuse 'key rotation' with 'key usage monitoring' or assume that manual triggers or external managers can satisfy the automatic rotation requirement, when in fact Cloud KMS provides a native rotation period setting that must be used.

26
MCQeasy

A company needs to ensure that all data stored in Cloud Storage is encrypted at rest with keys that they control and can rotate on demand. They also need to maintain an audit trail of key usage. Which Google Cloud service should they use?

A.Google-managed encryption keys
B.Customer-managed encryption keys (CMEK) in Cloud KMS
C.Customer-supplied encryption keys (CSEK)
D.Cloud HSM
AnswerB

CMEK in Cloud KMS allows the company to create, rotate, and manage their own keys. Cloud KMS logs key usage through Cloud Audit Logs, providing an audit trail. This option satisfies both the control and audit requirements for data at rest in Cloud Storage.

Why this answer

Customer-managed encryption keys (CMEK) in Cloud KMS give the company full control over key creation, rotation, and usage. Cloud KMS integrates with Cloud Audit Logs to record all key operations, providing the required audit trail. Google-managed keys offer no customer control, CSEK lack integrated auditing, and Cloud HSM is a backing option for CMEK rather than a standalone solution.

Exam trap

The trap here is confusing CSEK with CMEK; CSEK are not stored in Cloud KMS and do not provide an audit trail.

27
MCQeasy

A startup wants to grant a new employee read-only access to view all Compute Engine instances in a project. What is the minimum IAM role they should assign?

A.roles/owner
B.roles/compute.viewer
C.roles/iam.securityReviewer
D.roles/compute.admin
AnswerB

roles/compute.viewer grants read-only permission to list and get Compute Engine instances, resources, and related metadata across the project. It satisfies the least-privilege requirement without granting the modify or delete capabilities included in broader roles such as compute.admin.

Why this answer

The roles/compute.viewer role grants read-only access to Compute Engine resources, including the ability to list and view instances, without allowing modifications. This is the minimum IAM role that satisfies the requirement for read-only access to all Compute Engine instances in a project, as it provides the necessary permissions (e.g., compute.instances.list, compute.instances.get) without granting broader project-level or write permissions.

Exam trap

The trap here is that candidates may confuse roles/compute.viewer with roles/iam.securityReviewer, thinking the latter provides broader read access, but it lacks the specific Compute Engine permissions needed to view instances.

How to eliminate wrong answers

Option A is wrong because roles/owner grants full access to all resources in the project, including the ability to modify and delete instances, which far exceeds the required read-only access and violates the principle of least privilege. Option C is wrong because roles/iam.securityReviewer provides read access to IAM policies and security-related resources, but does not include the compute.instances.list or compute.instances.get permissions needed to view Compute Engine instances. Option D is wrong because roles/compute.admin grants full control over Compute Engine resources, including create, update, and delete operations, which is more permissive than the required read-only access.

28
MCQhard

A healthcare organization is storing sensitive patient data in Cloud Storage. They need to ensure that all objects are encrypted with a key managed by their on-premises HSM. Which encryption approach should they use?

A.Use Customer-Supplied Encryption Keys (CSEK) and store the key in a Secret Manager accessible only from the on-premises HSM.
B.Use Cloud External Key Manager (EKM) with a key hosted on the on-premises HSM.
C.Use Customer-Managed Encryption Keys (CMEK) with a Cloud KMS key that is generated from the on-premises HSM.
D.Encrypt each object client-side with a key from the on-premises HSM before uploading to Cloud Storage.
AnswerB

Cloud External Key Manager lets Cloud Storage use a customer-managed key held in the on-premises HSM, so the key never leaves the organisation's hardware. This satisfies the requirement that encryption keys remain managed by the on-premises HSM.

Why this answer

Cloud External Key Manager (EKM) allows you to use an external key management system, such as an on-premises HSM, to manage encryption keys for Google Cloud services. This approach meets the requirement because the key never leaves the HSM, and Cloud Storage uses the key via the EKM integration, ensuring the organization retains full control over the key lifecycle.

Exam trap

In Google PCA, the trap here is that candidates confuse CMEK with EKM: CMEK keys are stored in Cloud KMS, not on an external HSM. EKM allows using an external key manager like an on-premises HSM.

How to eliminate wrong answers

Option A is wrong because Customer-Supplied Encryption Keys (CSEK) require you to supply the raw key material with each API call, and storing the key in Secret Manager does not keep it exclusively on the on-premises HSM; the key must be provided to Google Cloud, which violates the requirement of key management solely by the on-premises HSM. Option C is wrong because Customer-Managed Encryption Keys (CMEK) use Cloud KMS to generate and manage the key, and while you can import a key from an on-premises HSM, the key is then stored and managed within Cloud KMS, not exclusively on the on-premises HSM. Option D is wrong because client-side encryption before upload does not use Cloud Storage's native encryption integration; it requires the organization to manage encryption and decryption outside of Cloud Storage, which is not the same as ensuring Cloud Storage encrypts objects with a key managed by the on-premises HSM.

29
MCQeasy

A data scientist needs read-only access to a Cloud Storage bucket containing training data. What is the least privileged IAM role to grant at the bucket level?

A.roles/storage.objectAdmin
B.roles/storage.objectCreator
C.roles/storage.admin
D.roles/storage.objectViewer
AnswerD

roles/storage.objectViewer grants read-only access to objects within a bucket, including listing and getting them, without write or delete permissions. Applied at bucket level it satisfies the least-privilege requirement for reading training data, unlike broader roles such as objectAdmin or storageAdmin.

Why this answer

Roles/storage.objectViewer grants read-only access to objects in a Cloud Storage bucket without allowing any write or administrative actions. This is the least privileged role that satisfies the requirement for read-only access to training data at the bucket level, as it only permits storage.objects.get and storage.objects.list permissions.

Exam trap

The trap here is that candidates often confuse roles/storage.objectViewer with roles/storage.objectAdmin or roles/storage.admin, mistakenly thinking broader roles are needed for read access, or they incorrectly assume roles/storage.objectCreator provides read capabilities.

How to eliminate wrong answers

Option A is wrong because roles/storage.objectAdmin grants full control over objects, including create, delete, and update permissions, which exceeds the read-only requirement. Option B is wrong because roles/storage.objectCreator only allows creating new objects but does not grant read access to existing objects, so it cannot fulfill the read-only need. Option C is wrong because roles/storage.admin provides full administrative control over the bucket, including modifying bucket metadata and IAM policies, which is far more permissive than read-only access.

30
MCQeasy

A company is deploying a web application on Compute Engine. They want to ensure that only authenticated users can access the application. Which Google Cloud service should they use?

A.Identity-Aware Proxy
B.Cloud Load Balancing
C.Cloud CDN
D.Cloud DNS
AnswerA

Identity-Aware Proxy performs authentication and authorisation at the application layer before requests reach the Compute Engine backend, verifying user identity and context. This enforces that only authenticated users access the application, satisfying the stated access constraint without network-level controls.

Why this answer

Identity-Aware Proxy (IAP) is the correct choice because it enforces access control at the edge of Google's network, verifying user identity and context before allowing traffic to reach the Compute Engine instance. IAP uses OAuth 2.0 and signed headers to authenticate users, ensuring only authorized requests are forwarded to the backend, without requiring any changes to the application itself.

Exam trap

The trap here is that candidates often confuse network-level services like Cloud Load Balancing or Cloud CDN with security controls, assuming they provide authentication simply because they sit in front of the application, but they lack any identity verification mechanism.

How to eliminate wrong answers

Option B (Cloud Load Balancing) is wrong because it distributes traffic across instances but does not authenticate users; it operates at Layer 4 or Layer 7 without any built-in identity verification. Option C (Cloud CDN) is wrong because it caches content at edge locations to reduce latency, but it does not enforce user authentication; it can be combined with IAP but alone provides no access control. Option D (Cloud DNS) is wrong because it translates domain names to IP addresses and has no mechanism for user authentication or authorization.

31
MCQhard

A financial services firm runs a regulated workload in a Google Cloud organization. Compliance requires that no resource in any project can be created outside a defined set of approved regions, and that violations are blocked before resource creation rather than reported afterward. The organization has many projects and new projects are created frequently. Which approach should the architect implement?

A.Deploy an organization policy using compute.restrictVpcPeering and rely on network topology to limit regions
B.Enable VPC Service Controls perimeters around each project and restrict egress to unapproved regions
C.Write a Cloud Asset Inventory feed that triggers a Cloud Function to delete non-compliant resources
D.Create an organization policy with the location restriction constraint (constraints/gcp.resourceLocations) applied at the organization node
AnswerD

An organization policy using the location restriction constraint inherits down the resource hierarchy, so every current and future project in the organization is covered without per-project configuration. It enforces the allowed regions at resource-creation time, which is exactly the preventive control the compliance team requires rather than a detective control.

Why this answer

Organization policies are preventive controls that inherit through the resource hierarchy, so a location restriction set at the organization node automatically applies to every existing and future project. VPC Service Controls, VPC peering constraints, and asset-based remediation either govern the wrong thing or act only after the fact, so none of them blocks resource creation in a prohibited region.

Exam trap

The trap here is confusing VPC Service Controls, which govern data access and exfiltration, with organization policies, which govern resource configuration and placement.

32
Matchingmedium

Match each GCP data processing service to its use case.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Stream and batch data processing (Apache Beam)

Managed Hadoop and Spark clusters

Asynchronous messaging for event ingestion

Visual data integration pipelines

Workflow orchestration (Apache Airflow)

Why these pairings

Dataflow is for unified stream/batch processing, Dataproc manages Spark/Hadoop, BigQuery is a serverless data warehouse, Pub/Sub is for messaging. Common confusions include mixing Dataflow with Dataproc and BigQuery with Pub/Sub.

33
MCQeasy

A multinational retailer must comply with a regulation stating that customer personal data collected in the European Union may not be stored or processed outside the EU, including by support staff. The company uses Google Cloud and wants a platform-level mechanism that enforces this at the data-residency level while still allowing the global analytics team to query aggregated, non-personal results. Which Google Cloud capability should the architect use as the foundation?

A.Assured Workloads with the EU data boundary and data residency controls enabled on the folder
B.Cloud KMS CMEK keys stored in an EU region and bound to all datasets
C.Cloud Data Loss Prevention templates applied to all BigQuery datasets holding customer data
D.VPC Service Controls perimeters around each EU project with restricted egress
AnswerA

Assured Workloads applies a compliance regime, such as data residency for the EU, to a folder and its child projects. It enforces controls including regional restrictions and personnel access limits so that data stays within the specified jurisdiction, while aggregated outputs can still be shared with the global team under the company's own controls.

Why this answer

Assured Workloads is purpose-built to apply regulatory compliance regimes, including data residency, to a folder of projects. It enforces location restrictions and personnel access controls for the chosen jurisdiction, which directly addresses the legal requirement. Data Loss Prevention, VPC Service Controls, and regional CMEK keys are useful supporting controls but none of them establishes or enforces residency on their own.

Exam trap

The trap here is choosing an encryption or network control because it sounds like it keeps data local, when residency is a policy and personnel-access problem that Assured Workloads is designed to solve.

34
MCQeasy

A company wants to restrict data exfiltration from its Google Cloud projects by preventing resources from copying data to external IP addresses. Which service should they use?

A.HTTPS Load Balancer
B.VPC Service Controls
C.Cloud Armor
D.Cloud NAT
AnswerB

VPC Service Controls create a security perimeter around resources to prevent data exfiltration.

Why this answer

VPC Service Controls is the correct choice because it creates a security perimeter around Google Cloud resources, such as BigQuery or Cloud Storage, and prevents data exfiltration by blocking access from outside the perimeter or to external IP addresses. It enforces context-aware access policies that can deny egress traffic to non-permitted destinations, directly addressing the requirement to restrict copying data to external IPs.

Exam trap

A common misconception is that Cloud NAT provides security for outbound traffic, but it actually enables outbound connectivity and does not prevent data exfiltration to external IPs. Candidates often confuse outbound internet access with exfiltration prevention.

How to eliminate wrong answers

Option A is wrong because an HTTPS Load Balancer distributes incoming traffic and does not enforce egress data exfiltration controls; it operates at Layer 7 for ingress only. Option C is wrong because Cloud Armor provides web application firewall (WAF) and DDoS protection for incoming HTTP/S traffic, not egress data exfiltration prevention. Option D is wrong because Cloud NAT allows resources without external IPs to initiate outbound connections to the internet, which would actually facilitate data exfiltration rather than prevent it.

35
Multi-Selecteasy

A company is designing a data processing pipeline in Google Cloud that must be HIPAA compliant. Which three security features should they implement? (Choose three.)

Select 3 answers
A.Encrypt data in transit using TLS
B.Enable Data Loss Prevention (DLP) for data classification
C.Use Cloud CDN for faster delivery
D.Implement VPC Service Controls to prevent data exfiltration
E.Use Cloud HSM for encryption keys
AnswersA, D, E

Required by HIPAA for data in transit.

Why this answer

Encrypting data in transit using TLS is a mandatory security control for HIPAA compliance because it protects electronic protected health information (ePHI) from interception during transmission over networks. TLS 1.2 or higher ensures that data moving between clients, services, and Google Cloud endpoints is encrypted, meeting the HIPAA Security Rule requirement for integrity and confidentiality of ePHI in transit.

Exam trap

The trap here is that candidates confuse data classification tools like DLP with mandatory security controls, or mistake performance features like Cloud CDN for compliance requirements, when HIPAA specifically requires encryption, access controls, and audit trails.

36
MCQhard

A healthcare company stores PHI in BigQuery. Compliance requires that analysts see masked values for patient names and MRNs, while a small data-engineering group must see unmasked values for pipeline troubleshooting. The policy must be enforced by BigQuery itself, independent of any application code. Which approach should the architect implement?

A.Create two separate datasets and grant analysts access only to the masked dataset, applying a view that selects hashed columns
B.Enable VPC Service Controls around the BigQuery project so only the data-engineering group can query the dataset
C.Apply row-level security filters on the table so analysts only see rows belonging to their region
D.Use BigQuery column-level security with policy tags in Data Catalog, granting the data-engineering group the Fine-Grained Reader role on the sensitive tags
AnswerD

Policy tags attached to columns enforce masking or denial at query time inside BigQuery, independent of application code. Analysts without the Fine-Grained Reader role on the tag receive masked or denied values, while the data-engineering group granted that role on the tag sees raw values, satisfying the split-visibility requirement declaratively.

Why this answer

BigQuery column-level security with Data Catalog policy tags enforces per-column access in the query engine. Sensitive columns are tagged, and only principals granted the Fine-Grained Reader role on that tag can read raw values. Analysts without the role receive masked or denied results, and engineers with the role see clear text, with no application changes needed.

Exam trap

The trap here is reaching for row-level security or dataset duplication when the requirement is specifically per-column value masking for different principals on the same table.

37
MCQhard

A government agency must retain Cloud Storage objects for seven years in a bucket that also serves live traffic. Regulators require that no user, including project owners, can delete or shorten retention during that period. The architect needs a control that satisfies this. Which should the architect configure?

A.A bucket lock applied after configuring a retention policy on the bucket.
B.Object Versioning combined with a lifecycle rule that deletes noncurrent versions after seven years.
C.A Cloud Storage retention policy set to seven years without locking the bucket.
D.A bucket-level IAM condition that denies storage.objects.delete when the request comes from outside the agency's VPC.
AnswerA

Setting a retention policy prevents object deletion until the retention period elapses, and locking the bucket makes the policy permanent so that no principal, including project owners, can remove or reduce it. This directly satisfies the regulatory requirement that retention cannot be shortened by anyone during the seven-year window.

Why this answer

A Cloud Storage retention policy enforces a minimum age before objects can be deleted or overwritten, and locking the bucket makes that policy permanent and irreversible. Locking removes the ability of any principal, including project owners, to delete the policy or shorten the retention period, which is exactly the immutability regulators require for the seven-year window.

Exam trap

The trap here is believing that an unlocked retention policy is sufficient for compliance, when without the bucket lock any administrator can remove or shorten the policy at will.

38
Multi-Selectmedium

A company is migrating to Google Cloud and needs to implement a least-privilege access model. Which THREE Google Cloud services or features support this goal? (Choose three.)

Select 3 answers
A.Cloud IAM Conditions
B.Cloud Audit Logs
C.VPC Service Controls
D.Cloud NAT
E.Organization Policy Service
AnswersA, C, E

Allow access based on attributes like time, IP, or resource type, enabling least privilege.

Why this answer

Cloud IAM Conditions allow you to define and enforce attribute-based, context-aware access control policies on Google Cloud resources. By specifying conditions such as time, resource type, or IP address in IAM policies, you can grant temporary or scoped permissions, ensuring users have only the access necessary for their specific task. This directly supports least-privilege by reducing standing privileges and preventing over-permissioning.

Exam trap

The trap here is confusing auditing and monitoring services (like Cloud Audit Logs) with access control mechanisms, leading candidates to select Cloud Audit Logs as a least-privilege tool when it only records actions without enforcing permissions.

39
Drag & Dropmedium

Drag and drop the steps to set up a shared VPC in Google Cloud for a multi-project environment into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The host project holds the VPC network. Service projects use the subnets. IAM roles control who can use the subnets.

40
MCQeasy

A small company wants to store sensitive files in Cloud Storage and ensure they are encrypted with a key that they control and rotate automatically every 90 days. They are currently using the default encryption provided by Google Cloud. They need a solution that is easy to manage and does not require manual key rotation. What should they do?

A.Use Cloud HSM to generate a key and handle encryption outside of Cloud Storage.
B.Create a Cloud KMS key ring and key with CMEK, set a rotation period of 90 days, and configure the bucket to use that key.
C.Use Customer-Supplied Encryption Keys (CSEK) and write a script to rotate the key every 90 days.
D.Continue using default encryption as it is automatically rotated by Google.
AnswerB

CMEK with a Cloud KMS key gives the company sole control of the encryption key, and configuring a 90-day rotation period automates rotation without manual intervention. The bucket references that key, replacing Google's default encryption, which offers no customer-controlled rotation.

Why this answer

Customer-Managed Encryption Keys (CMEK) via Cloud KMS allow the company to control the key while leveraging automatic rotation. By creating a key ring and key with a 90-day rotation period, and configuring the Cloud Storage bucket to use that key, the company meets the requirement for automated rotation without manual intervention. This solution is easy to manage and integrates natively with Cloud Storage, avoiding the complexity of external encryption or scripting.

Exam trap

The trap here is that candidates often confuse CMEK (customer-managed, automatic rotation) with CSEK (customer-supplied, manual rotation) or assume default encryption already meets the control requirement, but the question explicitly demands customer-controlled keys with automatic rotation.

How to eliminate wrong answers

Option A is wrong because Cloud HSM generates keys that are managed by the customer but encryption must be handled outside Cloud Storage, adding operational complexity and violating the 'easy to manage' requirement. Option C is wrong because Customer-Supplied Encryption Keys (CSEK) require the customer to supply the key with each API call and write a script for rotation, which is not automatic and contradicts the 'does not require manual key rotation' requirement. Option D is wrong because default encryption uses Google-managed keys, which the customer does not control, failing the requirement that they control the key.

41
MCQmedium

An engineering team runs workloads on Compute Engine instances in a single VPC. The security team wants the instances to reach Google APIs such as Cloud Storage and BigQuery without any traffic traversing the public internet, and without managing service account key files on disk. The architect must choose the configuration that meets both goals. Which approach should the architect recommend?

A.Deploy a third-party NAT gateway and route all Google API traffic through it with static service account keys
B.Configure Cloud VPN to an on-premises proxy that forwards API calls to Google
C.Enable Private Google Access on the subnet and attach a user-managed service account to the instances
D.Assign an external IP to each instance and configure firewall rules to allow egress to Google API IP ranges
AnswerC

Private Google Access lets instances without external IPs reach Google APIs and services using internal routing, so no traffic traverses the public internet. Attaching a user-managed service account lets the instance metadata server issue short-lived credentials, eliminating downloaded key files. Together they satisfy both the network and credential requirements.

Why this answer

Private Google Access allows instances that have no external IP address to reach Google APIs and services through internal Google routing, keeping traffic off the public internet. Attaching a user-managed service account lets the instance obtain short-lived tokens from the metadata server, so no long-lived key files are stored on disk. The other options either route traffic over the internet or retain static keys.

Exam trap

The trap here is treating Private Google Access as a complete solution while forgetting that credential management is a separate requirement, or assuming a NAT gateway keeps Google API traffic off the internet.

42
MCQmedium

An organization is implementing a data loss prevention (DLP) strategy for Cloud Storage. They want to automatically scan new objects uploaded to a specific bucket and redact sensitive data. Which service and configuration should they use?

A.Configure Cloud Armor with a WAF rule to inspect and redact data as it enters the bucket.
B.Enable Security Command Center (SCC) premium tier and configure it to scan the bucket for sensitive data.
C.Use Cloud DLP with a BigQuery external table to scan the bucket contents periodically.
D.Use Cloud Functions triggered by Cloud Storage events to call Cloud DLP API for each new object, and then store the redacted version.
AnswerD

Event-driven Cloud Functions fire on each object finalisation, invoking the Cloud DLP API to inspect and redact sensitive content before writing the sanitised object back. This satisfies automatic scanning of new uploads, which bucket-level DLP inspection alone cannot trigger per object.

Why this answer

It uses Cloud Functions as an event-driven compute service that triggers on Cloud Storage object finalize events. The function then calls the Cloud DLP API to inspect and redact sensitive data from the new object, and writes the redacted version back to the bucket. This provides automatic, near-real-time scanning and redaction for each uploaded object, aligning with the requirement for an automated DLP strategy.

Exam trap

The trap here is that candidates may confuse Cloud DLP's batch scanning capabilities (e.g., via BigQuery or Cloud Storage inspect jobs) with the need for real-time, event-driven processing, leading them to choose Option C instead of recognizing that Cloud Functions provide the necessary automatic trigger for each new object.

How to eliminate wrong answers

Option A is wrong because Cloud Armor is a web application firewall (WAF) that protects HTTP(S) load-balanced traffic, not a service that inspects or redacts data inside Cloud Storage buckets; it operates at the network edge, not on stored objects. Option B is wrong because Security Command Center (SCC) is a security and risk management platform that provides visibility and threat detection, but it does not perform automated redaction of sensitive data in Cloud Storage; it can identify misconfigurations or vulnerabilities but cannot modify object content. Option C is wrong because using Cloud DLP with a BigQuery external table requires periodic batch scanning of the bucket, which does not meet the requirement for automatic scanning of new objects as they are uploaded; it introduces latency and lacks event-driven, per-object processing.

43
MCQhard

An organization has a security policy that prohibits the use of external IP addresses on Compute Engine instances to reduce attack surface. They want to enforce this policy across all new and existing projects. Which approach should they use?

A.Use Organization Policy with constraint compute.vmExternalIpAccess
B.Use IAM conditions to prevent creation of instances with external IPs
C.Use Cloud Security Command Center to detect and alert on external IPs
D.Use VPC Firewall rules to block traffic to external IPs
AnswerA

The `compute.vmExternalIpAccess` organisation policy constraint directly enforces the no-external-IP requirement across every project in the organisation, denying instance creation or update when an external address is attached. Unlike per-project firewall rules or IAM controls, it applies hierarchically at the organisation node, satisfying the mandate for both new and existing projects.

Why this answer

The Organization Policy constraint `compute.vmExternalIpAccess` is the correct approach because it allows you to set a policy at the organization, folder, or project level that denies the assignment of external IP addresses to Compute Engine instances. This policy is enforced at resource creation time and applies to all new and existing VM instances, ensuring compliance with the security policy across the entire resource hierarchy. It directly prevents the use of external IPs, reducing the attack surface without requiring per-project or per-instance configuration.

Exam trap

The trap here is that candidates often confuse IAM conditions (which control who can perform an action) with Organization Policy constraints (which control what actions are allowed), leading them to choose IAM conditions as a preventive control when they only provide authorization-level restrictions, not resource-level enforcement.

How to eliminate wrong answers

Option B is wrong because IAM conditions can restrict who can create instances with external IPs, but they do not prevent the actual assignment of external IPs; a user with the compute.instances.create permission could still create an instance with an external IP if the condition is not properly scoped, and IAM conditions do not enforce the policy on existing instances. Option C is wrong because Cloud Security Command Center (SCC) is a detection and alerting tool that identifies misconfigurations after they occur, but it does not proactively enforce or prevent the use of external IPs; it only provides visibility and remediation recommendations. Option D is wrong because VPC Firewall rules control traffic to and from IP addresses, but they cannot prevent a VM from being assigned an external IP address; a VM with an external IP will still have that IP regardless of firewall rules, and firewall rules do not block the IP assignment itself.

44
MCQhard

A government agency must run sensitive analytics in BigQuery while ensuring that analysts can see aggregated results but never the raw values of specific personal data columns. Analysts use SQL and must not be able to bypass the restriction by writing their own queries. The agency also needs to record who queried which columns. Which combination should the architect use?

A.Encrypt the sensitive columns with a customer-managed key and grant analysts the crypto key decrypter role only for aggregate queries.
B.Create a view that omits the sensitive columns and grant analysts access only to the view, revoking access to the base table.
C.Grant analysts roles/bigquery.dataViewer on the dataset and rely on BigQuery's default access controls to prevent them from seeing sensitive columns.
D.Create a policy tag taxonomy in Data Catalog, assign a policy tag to the sensitive columns, and grant analysts the fine-grained reader role on the tag so they see masked values, while column access is recorded in audit logs.
AnswerD

Policy tags in Data Catalog applied to specific columns let BigQuery return masked values to principals who hold only the fine-grained reader role on the tag, while fully privileged principals see raw data. Because the masking is enforced at the column level by BigQuery itself, analysts cannot circumvent it by rewriting SQL. Data access audit logs then record the column-level reads for the compliance requirement.

Why this answer

Column-level security in BigQuery is delivered through policy tags in Data Catalog. Assigning a policy tag to the sensitive columns and granting analysts only the fine-grained reader role on that tag causes BigQuery to return masked values for those columns while still allowing aggregation over the rest of the table. Because enforcement happens inside the query engine, analysts cannot bypass it with custom SQL, and column access is captured in data access audit logs.

Exam trap

The trap here is assuming that dataset-level roles or views prevent analysts from reading sensitive columns, when only column-level policy tags enforce masking inside the query engine.

45
MCQeasy

A company wants to ensure that all access to their Cloud Storage bucket is logged for compliance purposes. Which type of audit log should they enable?

A.Admin Activity audit logs
B.Data Access audit logs
C.System Event audit logs
D.Access Transparency logs
AnswerB

Data Access audit logs record read and write operations on Cloud Storage objects, capturing who accessed bucket data and when. This satisfies the compliance requirement to log all access, unlike Admin Activity logs which only cover configuration changes.

Why this answer

Data Access audit logs (Option B) are required to log every API call that reads, writes, or deletes data in a Cloud Storage bucket, such as object GETs and PUTs. Admin Activity logs only record configuration changes, not data access, so they would not capture the read/write operations needed for compliance logging.

Exam trap

Candidates often confuse Admin Activity logs with Data Access logs, thinking that Admin Activity logs cover data access operations, but they only record configuration changes; Data Access logs are needed for actual data access auditing.

How to eliminate wrong answers

Option A is wrong because Admin Activity audit logs record only metadata or configuration changes (e.g., creating or deleting a bucket), not the actual data access events like reading or writing objects. Option C is wrong because System Event audit logs capture Google Cloud system actions (e.g., automatic maintenance or VM live migration), not user-driven data access to Cloud Storage. Option D is wrong because Access Transparency logs provide logs of Google personnel accessing your data, not your own users' access to Cloud Storage objects.

46
MCQeasy

A startup wants to encrypt data at rest in Cloud Storage using Customer-Managed Encryption Keys (CMEK). They have already created a Cloud KMS key ring and key. What additional step is required to enable CMEK for a new Cloud Storage bucket?

A.Enable the Cloud KMS API in the project where the bucket will reside.
B.Create a Cloud HSM key instead, as CMEK requires HSM.
C.Add a label to the key ring to associate it with the bucket.
D.Grant the Cloud Storage service account the Cloud KMS CryptoKey Encrypter/Decrypter role on the key.
AnswerD

CMEK requires the Cloud Storage service account to hold the CryptoKey Encrypter/Decrypter role on the KMS key, otherwise Cloud Storage cannot wrap and unwrap data encryption keys. Granting this IAM binding is the mandatory step after creating the key ring and key.

Why this answer

To use CMEK with Cloud Storage, the Cloud Storage service account must be granted the Cloud KMS CryptoKey Encrypter/Decrypter role on the specific key. This permission allows the bucket's underlying storage system to encrypt and decrypt objects using the customer-managed key. Without this IAM binding, the bucket cannot access the key, and CMEK operations will fail.

Exam trap

A common misconception is that enabling the Cloud KMS API or using Cloud HSM is required for CMEK, when the actual critical step is granting the Cloud KMS CryptoKey Encrypter/Decrypter role to the Cloud Storage service account on the key.

How to eliminate wrong answers

Option A is wrong because the Cloud KMS API is automatically enabled when you create a key ring or key via the console or gcloud, and it is not a prerequisite for CMEK on a bucket; the bucket itself does not need the KMS API enabled separately. Option B is wrong because CMEK supports both Cloud KMS software keys and Cloud HSM keys; HSM is not required, and the question explicitly states a Cloud KMS key has already been created. Option C is wrong because labels on a key ring are metadata tags and have no role in associating a key with a bucket; the association is done via IAM permissions on the key, not labels.

47
MCQhard

A multinational corporation operates in multiple regions and must comply with GDPR. They use Cloud Load Balancing to distribute traffic across regional backends. Their security team wants to block traffic from specific countries (e.g., non-EU countries) at the edge. What should they use?

A.Configure Cloud CDN to serve content only to EU-based users.
B.Use Cloud Armor security policies with geographic-based denylist rules.
C.Set VPC firewall rules to allow traffic only from EU IP ranges.
D.Configure Identity-Aware Proxy (IAP) to require user authentication from allowed countries.
AnswerB

Cloud Armor security policies attach to the load balancer's backend service and evaluate rules at the edge, including geographic denylists keyed on source country. This blocks non-EU traffic before it reaches regional backends, satisfying the GDPR constraint.

Why this answer

Cloud Armor security policies support geographic-based access control using denylist or allowlist rules that match client IP addresses against country-level geolocation data. This allows the security team to block traffic from specific countries at the edge, before it reaches the backend, which is the most efficient and compliant approach for GDPR enforcement.

Exam trap

The trap here is that candidates often confuse VPC firewall rules (which filter by IP ranges) with Cloud Armor's geolocation-based policies, or they assume Cloud CDN or IAP can enforce geographic access control, when in fact only Cloud Armor provides native country-level blocking at the edge.

How to eliminate wrong answers

Option A is wrong because Cloud CDN caches content but does not enforce geographic access control; it can serve cached content to any user regardless of location, and its 'geo restrictions' are only for signed URLs, not for blocking traffic at the edge. Option C is wrong because VPC firewall rules operate at the network layer and cannot reliably block traffic based on country-level geolocation; they only filter by IP ranges, which are not accurate for country-level blocking due to IP reassignment and lack of granularity. Option D is wrong because Identity-Aware Proxy (IAP) controls access based on user identity and context, not on the geographic origin of the IP address; it cannot block traffic at the edge based solely on country.

48
MCQhard

A financial services firm stores sensitive customer records in Cloud Storage and must ensure that only identities in its corporate domain can read the objects, that no object can ever be made publicly accessible, and that access decisions are evaluated centrally. The firm wants the least administrative overhead while keeping these guarantees across many buckets created by different teams. What should the architect implement?

A.Use a customer-managed encryption key for every bucket and grant roles/storage.objectAdmin only to a single service account that proxies all reads for the corporate domain.
B.Enable VPC Service Controls with a service perimeter around the projects and grant roles/storage.objectViewer to the domain using a Google Group.
C.Apply an organization policy constraint with the storage.publicAccessPrevention enforced across the organization, and grant bucket access through IAM conditions that restrict principals to the corporate domain.
D.Set each bucket's default object ACL to private and rely on Cloud Storage's default uniform bucket-level access to block public reads, while granting roles/storage.objectViewer to all authenticated users.
AnswerC

Organization policy constraints enforce the public access prevention setting across every project and bucket beneath the organization, so no team can override it. IAM conditions on role bindings can restrict access to principals whose email matches the corporate domain, letting the firm centralize access decisions without per-bucket ACL management. Together these controls meet the guarantee and minimize ongoing administration across many teams.

Why this answer

The firm needs a preventive control that no team can bypass and an access model that is scoped to the corporate domain. Enforcing the public access prevention organization policy makes the no-public-access guarantee inherited and non-overridable at lower levels. IAM conditions limiting principals to the corporate domain keep read access inside the firm while allowing centralized administration.

This pairing addresses both the exposure guarantee and the identity restriction with minimal per-bucket work.

Exam trap

The trap here is treating encryption as an access control when key possession does not grant or deny read permission on a Cloud Storage object.

49
MCQmedium

A financial services company runs a containerized trading platform on Google Kubernetes Engine (GKE). Compliance requires that all inter-pod traffic be encrypted without modifying application code, and that the encryption keys be managed by the company rather than Google. The security team wants to enforce this at the infrastructure level. Which approach should they take?

A.Configure Istio with mutual TLS (mTLS) and a custom certificate authority managed by the company.
B.Enable Application-layer Secrets Encryption with a Cloud KMS key on the GKE cluster.
C.Use VPC Service Controls to create a service perimeter around the GKE cluster.
D.Enable GKE network policy enforcement and create NetworkPolicy resources to allow only encrypted traffic.
AnswerA

Istio with mTLS encrypts all service-to-service traffic transparently without application changes. When you integrate Istio's certificate authority with a company-managed CA, the keys and certificates are controlled by the organization, satisfying the requirement that keys be company-managed. This approach enforces encryption at the infrastructure layer for all inter-pod communication.

Why this answer

Istio's mutual TLS encrypts all service-to-service traffic within the mesh without requiring application changes. By integrating Istio's certificate authority with a company-managed CA, the organization retains control over encryption keys. NetworkPolicy and VPC Service Controls do not encrypt traffic, and Application-layer Secrets Encryption only protects secrets at rest, not network data in transit.

Exam trap

The trap here is assuming that GKE NetworkPolicy or VPC Service Controls provide encryption, when they only control traffic flow or API perimeters.

50
MCQmedium

A company is designing a VPC Service Controls perimeter to protect data stored in Google Cloud. They need to allow access from their on-premises network via a Cloud VPN tunnel while blocking all internet-based access. What is the most secure and manageable approach?

A.Configure firewall rules to only allow traffic from the on-premises CIDR to the VPC.
B.Use Cloud VPN and Private Google Access to allow on-premises access without public IPs.
C.Configure a VPC Service Controls perimeter and create an access level that includes the on-premises CIDR range.
D.Use Cloud IAP (Identity-Aware Proxy) to restrict access based on identity and context.
AnswerC

An access level containing the on-premises CIDR range permits traffic arriving through the Cloud VPN tunnel while denying internet-originated requests. This satisfies both the on-premises access requirement and the block-all-internet constraint within one manageable perimeter.

Why this answer

VPC Service Controls (VPC SC) is the only Google Cloud-native mechanism that can create a security perimeter around managed services (like Cloud Storage, BigQuery) and restrict access based on an access level that includes the on-premises CIDR range. This ensures that only traffic originating from the on-premises network (via the Cloud VPN tunnel) is allowed, while all internet-based access is blocked, even if the request uses valid credentials. Firewall rules alone cannot restrict access to Google-managed APIs, and Private Google Access does not enforce a perimeter around services.

Exam trap

The trap here is that candidates often confuse network-level controls (firewall rules, Private Google Access) with service-level perimeter controls, mistakenly believing that blocking traffic at the VPC level is sufficient to protect Google-managed APIs that are accessed via external endpoints.

How to eliminate wrong answers

Option A is wrong because firewall rules only control traffic at the VPC network level and cannot block access to Google-managed APIs (e.g., Cloud Storage, BigQuery) that are accessed via external IPs; they do not create a service perimeter. Option B is wrong because Private Google Access allows on-premises traffic to reach Google APIs via private IPs but does not block internet-based access to those same APIs; it lacks the ability to define a perimeter that denies all external traffic. Option D is wrong because Cloud IAP controls access based on identity and context at the application layer, but it does not enforce network-level perimeter controls and cannot block access from the internet to the underlying Google Cloud services (e.g., Cloud Storage buckets) that are not fronted by IAP.

51
MCQmedium

A data engineer needs to analyze data in BigQuery but must mask personally identifiable information (PII) based on user roles. Which service should they use?

A.BigQuery column-level security
B.Cloud Key Management Service
C.Cloud Data Catalog
D.Cloud Data Loss Prevention (DLP)
AnswerA

BigQuery column-level security uses policy tags in Data Catalog to restrict access to specific columns, masking or denying PII according to the user's role. This satisfies the requirement to mask personally identifiable information based on user roles without duplicating datasets.

Why this answer

BigQuery column-level security allows you to apply fine-grained access controls to specific columns containing PII, such as by using policy tags to restrict access based on user roles. This directly meets the requirement to mask sensitive data in BigQuery without moving or duplicating data, as it integrates with Cloud IAM to enforce role-based access at query time.

Exam trap

A common trap in Google PCA exams is confusing Cloud DLP (which is for classification and de-identification before data storage) with BigQuery column-level security (which provides runtime access control based on roles). DLP does not enforce role-based masking at query time; column-level security with policy tags does.

How to eliminate wrong answers

Option B (Cloud Key Management Service) is wrong because it manages encryption keys for data at rest or in transit, not role-based masking or access control at the column level in BigQuery. Option C (Cloud Data Catalog) is wrong because it is a metadata management and discovery service for tagging and searching assets, not a tool for enforcing data masking or access policies. Option D (Cloud Data Loss Prevention) is wrong because while it can inspect and classify PII, it is not a runtime access control service; it is typically used for scanning and de-identification before ingestion, not for dynamic role-based masking within BigQuery queries.

52
MCQhard

A healthcare company stores patient records in a Cloud Storage bucket. Compliance requires that all data be encrypted with customer-managed keys, and that the company can revoke access to the data by disabling the key. They also need to audit every key usage. Which approach should they take?

A.Use Customer-Managed Encryption Keys (CMEK) with Cloud KMS and enable Cloud Audit Logs for Cloud KMS.
B.Use default Google encryption and configure a Cloud Storage retention policy.
C.Use Customer-Supplied Encryption Keys (CSEK) and enable Cloud Audit Logs for Cloud Storage.
D.Use Google-managed encryption keys (GMEK) and enable Cloud Audit Logs for Cloud Storage.
AnswerA

CMEK allows the customer to manage keys in Cloud KMS, including disabling or destroying them to revoke access. Enabling Cloud Audit Logs for Cloud KMS records all key usage, satisfying the audit requirement. This approach meets both the encryption control and auditability needs for compliance.

Why this answer

Customer-Managed Encryption Keys (CMEK) in Cloud KMS allow the organization to control the encryption key lifecycle, including disabling the key to revoke access to data. Enabling Cloud Audit Logs for Cloud KMS provides an audit trail of all key operations, which is essential for compliance. This combination meets both the encryption control and auditing requirements.

Exam trap

The trap here is assuming that Customer-Supplied Encryption Keys (CSEK) provide the same centralized management and audit capabilities as CMEK, but CSEK keys are managed externally and lack integrated audit logging.

53
Multi-Selectmedium

A retail company is building a new application on Google Cloud. The security team requires that all data at rest be encrypted with keys the company manages, that key usage be auditable, and that the application on Compute Engine never store long-lived credentials on disk. The architect is selecting controls for the design. (Choose two.)

Select 2 answers
A.Enable Cloud External Key Manager with a third-party provider to hold the root key material for all disks and databases.
B.Use Google-managed encryption keys for the disks and rely on Cloud Audit Logs to record who accessed the data.
C.Store a service account key JSON file in Secret Manager and mount it into the instance at boot through a startup script.
D.Create a Cloud KMS key ring in the same region as the data and use a customer-managed encryption key (CMEK) to encrypt the disks and databases.
E.Attach a service account to the Compute Engine instances and use the metadata server to obtain short-lived access tokens for Google Cloud APIs.
AnswersD, E

CMEK lets the company own the key lifecycle and rotate or disable keys on its own schedule, which satisfies the requirement that the company manage the keys. Cloud KMS records key usage in Cloud Audit Logs, so every wrap and unwrap operation is attributable. Placing the key ring in the same region as the data also keeps the encryption path local and reduces latency for the data services using the key.

Why this answer

The two requirements are company-controlled encryption keys and no long-lived credentials on the instances. Customer-managed encryption keys in Cloud KMS satisfy the first, with audit logging of key use built in. Attaching a service account and pulling short-lived tokens from the metadata server satisfies the second, because the workload never needs a downloaded key file.

Together they cover the mandated controls without adding an external key manager dependency.

Exam trap

The trap here is assuming that storing a service account key in Secret Manager makes it acceptable, when the credential is still long-lived and still lands on the instance.

54
MCQeasy

A security team wants to receive alerts when a user attempts to grant the 'roles/owner' role to a member outside of the organization's domain. Which log filter should they use to create a log-based metric?

A.Filter on Admin Activity log type with 'protoPayload.methodName="SetIamPolicy" AND protoPayload.serviceName="cloudresourcemanager.googleapis.com" AND NOT protoPayload.request.policy.bindings: member: "example.com"'.
B.Filter on Data Access log type with 'protoPayload.methodName="google.iam.v1.IAMPolicy.SetIamPolicy"'.
C.Filter on Admin Activity logs for 'resource.type="gce_instance" AND protoPayload.methodName="compute.instances.setServiceAccount"'.
D.Filter on System Event logs with a query for 'resource.type="project" AND protoPayload.response.status.code=7'.
AnswerA

This filter catches IAM policy changes where members are not from the allowed domain.

Why this answer

It uses the Admin Activity audit log type, which captures IAM policy changes, and filters for the SetIamPolicy method on the cloudresourcemanager service. The condition NOT protoPayload.request.policy.bindings: member: "example.com" ensures alerts are triggered only when the owner role is granted to a member outside the organization's domain, matching the security requirement exactly.

Exam trap

In the Google PCA exam, the distinction between Admin Activity logs (for configuration changes like IAM) and Data Access logs (for data reads) is often tested. Candidates mistakenly choose Data Access logs because they associate IAM with 'access control' rather than administrative operations.

How to eliminate wrong answers

Option B is wrong because Data Access logs record read operations on resource data, not IAM policy modifications; SetIamPolicy is an administrative write operation and appears only in Admin Activity logs. Option C is wrong because it filters on compute.instances.setServiceAccount, which changes the service account attached to a VM instance, not the IAM policy granting the owner role to a user. Option D is wrong because System Event logs track Google Cloud system actions (e.g., maintenance events), not user-driven IAM policy changes, and the filter for response.status.code=7 (PERMISSION_DENIED) would only catch failed attempts, not successful grants.

55
MCQhard

A multinational corporation must comply with GDPR and requires that all customer data stored in BigQuery be encrypted using customer-managed encryption keys (CMEK) and that the keys are stored in a specific region. Which combination of steps should they take?

A.Enable default encryption at rest in BigQuery and use Organization Policies to restrict key location
B.Create a Cloud KMS key ring and crypto key in the desired region, then associate the BigQuery dataset with the CMEK key using DDL
C.Create a Cloud HSM key, then use Cloud DLP to automatically encrypt the data before loading into BigQuery
D.Use Cloud External Key Manager (EKM) to integrate with an on-premises key management system
AnswerB

Creating the Cloud KMS key ring and crypto key in the required region, then associating the BigQuery dataset with that CMEK key via DDL, satisfies both GDPR constraints: customer-managed keys and regional key residency. BigQuery then encrypts data with that key.

Why this answer

It directly fulfills the requirement: creating a Cloud KMS key ring and crypto key in the desired region, then associating the BigQuery dataset with that CMEK key using DDL (e.g., `ALTER SCHEMA mydataset SET OPTIONS(kms_key_name='...')`). This ensures that all data at rest in BigQuery is encrypted with a customer-managed key stored in a specific regional location, as mandated by GDPR for data residency and control.

Exam trap

A common pitfall is that candidates may confuse Cloud DLP or EKM as valid methods for BigQuery encryption at rest, when only CMEK via Cloud KMS with DDL association meets the specific requirement of regional key storage and customer control.

How to eliminate wrong answers

Option A is wrong because enabling default encryption at rest in BigQuery uses Google-managed keys, not customer-managed encryption keys (CMEK), and Organization Policies can restrict key location but do not enforce CMEK usage or provide customer-managed key control. Option C is wrong because Cloud HSM keys are a type of CMEK, but using Cloud DLP to encrypt data before loading into BigQuery is not the correct method; DLP is for data classification and de-identification, not for native BigQuery encryption at rest with CMEK, and it does not associate the key with the dataset. Option D is wrong because Cloud External Key Manager (EKM) integrates with an external key management system, but it does not store the keys in a specific Google Cloud region; the keys remain external, and BigQuery CMEK requires keys to be in Cloud KMS (including HSM) to enforce regional key location.

56
MCQmedium

A healthcare company stores patient records in Cloud Storage buckets across several projects. Compliance auditors require that no object can ever be made publicly readable, even by a project Owner, and that any attempt to do so must be blocked centrally. The security team must enforce this without breaking existing application access. What should they do?

A.Create an organization policy with the `storage.publicAccessPrevention` constraint set to enforced at the organization node.
B.Grant the `roles/storage.admin` role only to a dedicated security group and remove it from all project Owners.
C.Enable uniform bucket-level access on every bucket and rely on IAM conditions to deny public members.
D.Configure VPC Service Controls perimeters around each project to restrict access to Cloud Storage.
AnswerA

The `storage.publicAccessPrevention` organization policy constraint, enforced at the organization node, blocks any attempt to grant `allUsers` or `allAuthenticatedUsers` access to Cloud Storage buckets and objects, including by project Owners. Because it is inherited downward, it protects every project without altering existing IAM bindings for legitimate service accounts and users, so application access continues to work.

Why this answer

The `storage.publicAccessPrevention` organization policy constraint is the only mechanism here that centrally and preventively blocks public access grants at the organization level, regardless of a principal's project-level permissions. Because organization policies are inherited, enforcing it once at the org node covers all current and future projects while leaving legitimate IAM bindings untouched.

Exam trap

The trap here is assuming that removing broad IAM roles or enabling uniform bucket-level access prevents public exposure, when only the public access prevention organization policy constraint actively blocks public grants.

57
MCQmedium

An e-commerce company exposes a public API through an external HTTP(S) load balancer on Google Cloud. The security team wants to block traffic from known malicious IP ranges and apply rate limiting per client IP, while keeping legitimate customers unaffected. They want the least operational overhead and no changes to backend applications. What should they do?

A.Deploy Cloud Armor security policies with IP deny rules and a rate-based ban rule, and attach the policy to the load balancer's backend service.
B.Configure Cloud CDN with signed URLs and require all API clients to authenticate before reaching the backend.
C.Use Identity-Aware Proxy to require Google account authentication for all API requests.
D.Create a VPC firewall rule that denies traffic from the malicious IP ranges to the load balancer's backend instances.
AnswerA

Cloud Armor security policies attach to the backend service of an external HTTP(S) load balancer and can combine IP denylists with rate-based ban rules that throttle abusive clients per source IP. This requires no backend changes, is managed centrally, and blocks malicious ranges while allowing legitimate traffic, matching the least-overhead requirement.

Why this answer

Cloud Armor is the native edge security service for external HTTP(S) load balancers, attaching at the backend service where it can evaluate client IP rules and rate-based bans before traffic reaches backends. This satisfies both blocking malicious ranges and per-client-IP throttling without touching application code or managing instance-level firewalls.

Exam trap

The trap here is reaching for VPC firewall rules, which operate on backend instances and cannot see the original client IP behind an HTTP(S) load balancer, instead of edge-level Cloud Armor policies.

58
MCQeasy

A company is migrating sensitive customer data to Google Cloud. They need to ensure data is encrypted at rest and in transit. Which Google Cloud service provides a centralized way to manage encryption keys used by Google Cloud services?

A.Cloud HSM
B.Cloud External Key Manager (Cloud EKM)
C.Cloud Key Management Service (Cloud KMS)
D.Secret Manager
AnswerC

Cloud KMS centralises creation, rotation and access control of customer-managed encryption keys, and integrates with Google Cloud services for envelope encryption at rest and in transit. This satisfies the requirement for one centralised key management service.

Why this answer

Cloud KMS is the correct choice because it provides a centralized, managed service for creating, rotating, and destroying encryption keys used by Google Cloud services. It integrates directly with services like Cloud Storage, BigQuery, and Compute Engine to enforce encryption at rest, and it supports customer-managed encryption keys (CMEK) for granular control. For data in transit, Cloud KMS can be used to manage keys for TLS or application-level encryption, though Google Cloud automatically encrypts all network traffic by default.

Exam trap

Google Cloud often tests the distinction between Cloud KMS as the centralized key management service and Cloud HSM as a hardware-backed option within Cloud KMS, leading candidates to choose Cloud HSM when the question asks for the centralized service.

How to eliminate wrong answers

Option A is wrong because Cloud HSM is a hardware security module service that provides dedicated, FIPS 140-2 Level 3 validated hardware for key operations, but it is not the centralized key management service; it is an option within Cloud KMS for higher security requirements. Option B is wrong because Cloud External Key Manager (Cloud EKM) allows you to manage keys outside of Google Cloud using an external key management partner, but it is not a centralized Google Cloud service for managing encryption keys used by Google Cloud services; it is for keys stored externally. Option D is wrong because Secret Manager is designed to store and manage secrets such as API keys, passwords, and certificates, not encryption keys for encrypting data at rest or in transit across Google Cloud services.

59
Drag & Dropmedium

Drag and drop the steps to configure a Cloud Load Balancer with a backend service consisting of Compute Engine instances into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Health checks ensure traffic only goes to healthy instances; URL map defines routing; forwarding rule exposes the IP.

60
MCQmedium

A company wants to restrict access to a Cloud Storage bucket so that only objects encrypted with a specific Cloud KMS key can be read. Which approach should they use?

A.Enable Key Access Justifications on the Cloud KMS key and allow access only for justified requests.
B.Set a bucket policy that denies access if the object's encryption type is not CMEK.
C.Use IAM conditions with the resource name condition 'resource.name.startsWith("projects/_/buckets/example-bucket/objects/")' and 'resource.hasTag("kmsKeyName", "projects/p/locations/l/keyRings/kr/cryptoKeys/ck")'.
D.Configure VPC Service Controls to include the bucket and the Cloud KMS key resource.
AnswerA

Incorrect. Key Access Justifications provide logging and justification for key usage but do not control read access to objects based on encryption key.

Why this answer

To restrict access to a Cloud Storage bucket so that only objects encrypted with a specific Cloud KMS key can be read, the company should enable Key Access Justifications (KAJ) on the Cloud KMS key and allow access only for justified requests. KAJ provides the ability to enforce access policies based on the justification provided for a key operation, effectively tying object access to the specific key. Option B is incorrect because Cloud Storage bucket policies do not support conditions on `request.object.encryption.type`; that attribute is not a valid IAM condition for Cloud Storage.

Option C is incorrect because `resource.hasTag` is not a valid IAM condition attribute for Cloud Storage objects. Option D is incorrect because VPC Service Controls provide perimeter-based security but do not restrict access based on the encryption key of individual objects.

Exam trap

The trap is that candidates may think a bucket policy can enforce encryption-key-based access using a condition like `request.object.encryption.type`, but Cloud Storage IAM conditions do not support that attribute. The correct mechanism is Key Access Justifications on the Cloud KMS key.

How to eliminate wrong answers

Option A is wrong because Key Access Justifications (KAJ) are used to provide justifications for Cloud KMS key access requests, not to restrict bucket access based on encryption key type; KAJ does not filter object-level access. Option B is wrong because bucket policies cannot directly inspect or condition on the encryption type of individual objects; the condition 'object's encryption type is not CMEK' is not a supported attribute in bucket policy conditions. Option D is wrong because VPC Service Controls (VPC-SC) control network-level access to services and resources, but they cannot enforce that only objects encrypted with a specific KMS key are readable; VPC-SC operates on service perimeters, not object-level encryption attributes.

61
Multi-Selecthard

Which THREE Google Cloud services can be used to implement a zero-trust architecture for network security? (Choose three.)

Select 3 answers
A.Cloud Armor
B.Access Context Manager (ACM)
C.Identity-Aware Proxy (IAP)
D.VPC Networks
E.Cloud VPN
AnswersA, B, C

Cloud Armor provides WAF and DDoS protection at the edge, enforcing security policies.

Why this answer

Cloud Armor is correct because it provides web application firewall (WAF) and DDoS protection at the edge of Google's network, enforcing security policies based on IP addresses, geo-locations, and Layer 7 attributes. This aligns with zero-trust principles by inspecting and filtering traffic before it reaches the application, ensuring that only authorized requests are allowed, regardless of the network perimeter.

Exam trap

The trap here is that candidates often confuse network-level connectivity services (like VPC Networks and Cloud VPN) with security controls, mistakenly thinking that encrypting traffic or segmenting networks alone satisfies zero-trust requirements, when zero-trust actually demands identity- and context-aware access enforcement at the application layer.

62
MCQeasy

A company wants to use Cloud Armor to protect their HTTP load balancer from SQL injection attacks. Which rule action should they configure to block malicious requests?

A.Use a pre-configured WAF rule that includes 'evaluatePreconfiguredExpr('sqli-stable')' with action 'deny(403)'.
B.Configure a rate-limiting rule with action 'rateLimit' to throttle traffic from suspicious IPs.
C.Create a rule that redirects traffic to a reCAPTCHA challenge for validation.
D.Set a security policy rule with action 'deny(403)' and a simple condition on the user-agent header.
AnswerA

Cloud Armor's pre-configured WAF rules use ModSecurity-style expressions; 'sqli-stable' targets SQL injection signatures, and the 'deny(403)' action blocks matching requests at the load balancer edge. This satisfies the requirement to block, rather than merely log, malicious SQL injection traffic.

Why this answer

Cloud Armor's pre-configured WAF rules include 'evaluatePreconfiguredExpr('sqli-stable')', which specifically detects SQL injection patterns in HTTP requests. Applying the 'deny(403)' action blocks malicious requests by returning a 403 Forbidden status, preventing the attack from reaching the backend. This is the correct approach because Cloud Armor WAF rules are purpose-built for application-layer threats like SQL injection.

Exam trap

Candidates often mistakenly think that any 'deny' action or generic security policy can block SQL injection, but the key is using Cloud Armor's pre-configured WAF rule specifically designed to inspect for injection patterns, not just a blanket deny on headers or rate limits.

How to eliminate wrong answers

Option B is wrong because rate-limiting throttles traffic volume but does not inspect request content for SQL injection patterns, so it cannot block specific malicious payloads. Option C is wrong because redirecting to a reCAPTCHA challenge adds friction for users but does not filter SQL injection attempts; it is designed for bot mitigation, not content-based attack detection. Option D is wrong because a simple condition on the user-agent header is a basic filter that cannot identify SQL injection syntax; it lacks the signature-based or behavioral analysis needed to detect injection attacks.

63
MCQeasy

A company wants to automatically rotate cryptographic keys on a schedule without manual intervention. Which service should they use?

A.Cloud Key Management Service (KMS)
B.Secret Manager
C.Cloud Audit Logs
D.Cloud IAM
AnswerA

Cloud KMS supports automatic, scheduled rotation of cryptographic keys, satisfying the requirement for rotation without manual intervention. You configure a rotation period and the service generates new key versions on that schedule, while older versions remain available for decryption. This removes the operational burden of manual rotation entirely.

Why this answer

Cloud KMS provides built-in key rotation capabilities that allow you to automatically rotate cryptographic keys on a schedule (e.g., every 90 days) without manual intervention. You define a rotation period, and KMS automatically generates a new primary key version while retaining older versions for decryption of existing data. This is the correct service because it is specifically designed for managing encryption keys with automated lifecycle policies.

Exam trap

Google often tests the distinction between key management (KMS) and secret storage (Secret Manager), leading candidates to confuse automated key rotation with simple secret versioning.

How to eliminate wrong answers

Option B (Secret Manager) is wrong because Secret Manager is designed to store and manage secrets like API keys, passwords, and certificates, not to perform automated cryptographic key rotation; it lacks native key rotation scheduling. Option C (Cloud Audit Logs) is wrong because Cloud Audit Logs records API activities and access logs but does not manage or rotate cryptographic keys. Option D (Cloud IAM) is wrong because Cloud IAM controls access permissions and identities but has no capability to rotate keys; it is a policy engine, not a key management service.

64
MCQmedium

A company uses Google Cloud Armor to protect their HTTP load balancer from OWASP Top 10 attacks. After deploying a security policy with pre-configured WAF rules, they notice that some legitimate user requests are being blocked because they match a rule incorrectly. The security team wants to fine-tune the rules to reduce false positives while maintaining strong protection. They also want to evaluate the impact of changes before enforcing them. What should they do?

A.Disable the WAF rules entirely and implement IP-based allowlists.
B.Set the WAF rules to 'preview' mode to test their impact without blocking traffic, then adjust thresholds or exclusions based on logs.
C.Add a higher priority allow rule to permit the traffic that is being incorrectly blocked.
D.Remove the WAF rules and rely solely on rate limiting to protect the application.
AnswerB

Preview mode logs which requests would have been blocked without enforcing the action, letting the team measure false positives and tune thresholds or exclusions before enforcement. This satisfies both the fine-tuning and pre-enforcement evaluation requirements while preserving protection.

Why this answer

Google Cloud Armor's 'preview' mode allows you to apply a security policy to a backend service or load balancer without actually blocking traffic. Instead, all matched requests are logged, enabling you to analyze false positives in the logs before enforcing the rules. This approach lets you fine-tune thresholds, add exclusions, or adjust rule priorities based on real traffic patterns, reducing false positives while maintaining strong protection.

Exam trap

The trap here is that candidates may think adding a higher priority allow rule (Option C) is a valid fine-tuning approach, but it actually creates a security bypass rather than reducing false positives through proper rule adjustment.

How to eliminate wrong answers

Option A is wrong because disabling WAF rules entirely removes protection against OWASP Top 10 attacks, and IP-based allowlists only permit specific source IPs, which is not a scalable or effective defense against application-layer attacks. Option C is wrong because adding a higher priority allow rule would permit the traffic unconditionally, bypassing the WAF rules and potentially allowing malicious requests that match the same pattern, thus weakening security. Option D is wrong because removing WAF rules and relying solely on rate limiting does not protect against OWASP Top 10 attacks such as SQL injection or cross-site scripting, which require content inspection.

65
MCQmedium

A company hosts a web application on Google Kubernetes Engine (GKE) and wants to protect against SQL injection attacks. Which service should they configure?

A.Identity-Aware Proxy (IAP)
B.Cloud Armor
C.Cloud Audit Logs
D.Container Analysis
AnswerB

Cloud Armor is Google Cloud's edge security service, applying WAF rules to external HTTP(S) load balancers in front of GKE workloads, and its preconfigured SQL injection ruleset blocks malicious query strings before they reach the application.

Why this answer

Cloud Armor is the correct choice because it provides web application firewall (WAF) capabilities that can inspect HTTP/HTTPS traffic and block SQL injection attempts using preconfigured rules (e.g., the OWASP Top 10 rule set). It integrates directly with GKE via HTTP(S) Load Balancing, allowing you to enforce security policies at the edge before requests reach your application.

Exam trap

Candidates often confuse identity-based access controls (IAP) with content-based threat detection (Cloud Armor). IAP controls who can access the application, while Cloud Armor protects against attacks like SQL injection at the web application firewall layer.

How to eliminate wrong answers

Option A is wrong because Identity-Aware Proxy (IAP) controls access based on user identity and context, not traffic content; it cannot inspect payloads for SQL injection patterns. Option C is wrong because Cloud Audit Logs record API operations and access events for compliance, but they do not actively filter or block malicious requests. Option D is wrong because Container Analysis scans container images for vulnerabilities (e.g., in OS packages or libraries), but it does not protect against runtime application-layer attacks like SQL injection.

Ready to test yourself?

Try a timed practice session using only Design for security and compliance questions.