PSE-4

PSE-4

Professional Development

27 Qs

quiz-placeholder

Similar activities

Day 8 Quiz - Cloud Concepts & Wireless

Day 8 Quiz - Cloud Concepts & Wireless

Professional Development

26 Qs

Google Workspace for Education

Google Workspace for Education

Professional Development

22 Qs

GSuite Basics

GSuite Basics

Professional Development

25 Qs

Teacher's Training

Teacher's Training

Professional Development

22 Qs

QuizzaMania

QuizzaMania

Professional Development

23 Qs

Pro-DevOps-2

Pro-DevOps-2

Professional Development

31 Qs

CompTIA Security+ Quiz

CompTIA Security+ Quiz

Professional Development

25 Qs

AWS CSA Prep

AWS CSA Prep

Professional Development

25 Qs

PSE-4

PSE-4

Assessment

Quiz

Professional Development

Professional Development

Medium

Created by

Balamurugan R

Used 41+ times

FREE Resource

27 questions

Show all answers

1.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Your privacy team uses crypto-shredding (deleting encryption keys) as a strategy to delete personally identifiable information (PII). You need to implement this practice on Google Cloud while still utilizing the majority of the platform's services and minimizing operational overhead. What should you do?

Use client-side encryption before sending data to Google Cloud, and delete encryption keys on-premises.

Use Cloud External Key Manager to delete specific encryption keys.

Use customer-managed encryption keys to delete specific encryption keys.

Use Google default encryption to delete specific encryption keys.

2.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

For production projects, you must centralise your team's logs. You want your team to be able to use Logs Explorer to search and analyse logs.

What are your options?

Enable Cloud Monitoring workspace, and add the production projects to be monitored.

Use Logs Explorer at the organization level and filter for production project logs.

Create an aggregate org sink at the parent folder of the production projects, and set the destination to a Cloud Storage bucket.

Create an aggregate org sink at the parent folder of the production projects, and set the destination to a logs bucket.

3.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

You need to use Cloud External Key Manager to create an encryption key to encrypt specific BigQuery data at rest in Google Cloud. Which steps should you do first?

1. Create or use an existing key with a unique uniform resource identifier (URI) in your Google Cloud project. 2. Grant your Google Cloud project access to a supported external key management partner system.

1. Create or use an existing key with a unique uniform resource identifier (URI) in Cloud Key Management Service (Cloud KMS). 2. In Cloud KMS, grant your Google Cloud project access to use the key.

1. Create or use an existing key with a unique uniform resource identifier (URI) in a supported external key management partner system. 2. In the external key management partner system, grant access for this key to use your Google Cloud project.

1. Create an external key with a unique uniform resource identifier (URI) in Cloud Key Management Service (Cloud KMS). 2. In Cloud KMS, grant your Google Cloud project access to use the key.

4.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Your company's cloud security policy dictates that VM instances should not have an external IP address. You need to identify the Google Cloud service that will allow VM instances without external IP addresses to connect to the internet to update the VMs. Which service should you use?

Identity Aware-Proxy

Cloud NAT

TCP/UDP Load Balancing

Cloud DNS

5.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

You want to make sure that your organization's Cloud Storage buckets cannot have data publicly available to the internet. You want to enforce this across all Cloud Storage buckets. What should you do?

Remove Owner roles from end users, and configure Cloud Data Loss Prevention.

Remove Owner roles from end users, and enforce domain restricted sharing in an organization policy.

Configure uniform bucket-level access, and enforce domain restricted sharing in an organization policy.

Remove *.setIamPolicy permissions from all roles, and enforce domain restricted sharing in an organization policy.

6.

MULTIPLE SELECT QUESTION

45 sec • 1 pt

Your company intends to migrate the majority of its IT infrastructure to Google Cloud. They want to leverage their existing on-premises Active Directory as an identity provider for Google Cloud. Which two steps should you take to integrate the company's on-premises Active Directory with Google Cloud and configure access management? (Choose two.)

Use Identity Platform to provision users and groups to Google Cloud.

Use Cloud Identity SAML integration to provision users and groups to Google Cloud.

Install Google Cloud Directory Sync and connect it to Active Directory and Cloud Identity.

Create Identity and Access Management (IAM) roles with permissions corresponding to each Active Directory group.

Create Identity and Access Management (IAM) groups with permissions corresponding to each Active Directory group.

7.

MULTIPLE SELECT QUESTION

45 sec • 1 pt

You are in charge of creating a new Google Cloud organization for your company. Which two actions should you take when creating the super administrator accounts? (Choose two.)

Create an access level in the Google Admin console to prevent super admin from logging in to Google Cloud.

Disable any Identity and Access Management (IAM) roles for super admin at the organization level in the Google Cloud Console.

Use a physical token to secure the super admin credentials with multi-factor authentication (MFA).

Use a private connection to create the super admin accounts to avoid sending your credentials over the Internet.

Provide non-privileged identities to the super admin users for their day-to-day activities.

Create a free account and access millions of resources

Create resources
Host any resource
Get auto-graded reports
or continue with
Microsoft
Apple
Others
By signing up, you agree to our Terms of Service & Privacy Policy
Already have an account?