QuestionQ1
Configuring accessYour organization has engaged a small, temporary partner team for 18 months. The temporary team will work with your DevOps team to develop your organization’s application hosted on Google Cloud. You must grant the temporary partner team access to your application’s Google Cloud resources and ensure partner employees lose that access if they are removed from their employer’s organization. What should you do?
QuestionQ2
Configuring accessYour security team wants to lower the risk that user-managed keys are mishandled or compromised. To do this, you must stop developers from creating user-managed service account keys for projects in their organization. How should this be enforced?
Community Discussion
QuestionQ3
Managing operationsYour organization uses Vertex AI Workbench Instances. You must ensure that newly deployed Instances are automatically kept current and that users cannot inadvertently change operating-system settings. What should you do?
Community Discussion
QuestionQ4
Supporting compliance requirementsYou work for a multinational organization with systems deployed across multiple cloud providers, including Google Cloud. Your organization operates an extensive on-premises security information and event management (SIEM) system. New security-compliance regulations require relevant Google Cloud logs to be seamlessly integrated with the existing SIEM, providing a unified view of security events.
You need to implement a solution that exports Google Cloud logs to the on-premises SIEM using a push-based, near-real-time approach. You must prioritize fault tolerance, security, and autoscaling capabilities. In particular, you must ensure that logs are resent if a log delivery fails. What should you do?
Community Discussion
QuestionQ5
Securing communications and establishing boundary protectionYour organization is moving to Google Cloud. You need to ensure that only trusted container images are deployed to Google Kubernetes Engine (GKE) clusters in a project. Containers must be deployed from a centrally managed Container Registry and be signed by a trusted authority.
What should you do?
Community Discussion