Font size
Worksheetsgcloud 6-11
Total questions: 52
Worksheet time: 26mins
Which Google Cloud service provides defense against infrastructure and application Distributed Denial of Service (DDoS) attacks?
Google Cloud Armor
Cloud Load Balancing
Cloud DNS
Cloud CDN
Which two of the following statements are true about Google Cloud Armor?
Google Cloud Armor protection is delivered at the edge of Google’s network
Google Cloud Armor is a ransomware defense service
Google Cloud Armor is not currently compatible with any third-party partner security products
Google Cloud Armor enforces access control based on IPv4 and IPv6 addresses or CIDRs
Which IAM role contains permissions to create, modify, and delete networking resources, except for firewall rules and SSL certificates?
Network viewer
Security administrator
Network administrator
Security viewer
Which type of IAM member belongs to an application or virtual machine instead of an individual end user?
Cloud Identity domain
Google group
Service account
Google account
What is the primary purpose of Packet Mirroring in network security?
To redirect traffic to a different network interface
To filter out unwanted traffic from a network
To create a duplicate copy of network traffic for analysis
To encrypt network traffic for privacy
Which of the following is a key benefit of using Packet Mirroring for network security analysis?
It automatically patches vulnerabilities in software
It directly prevents cyberattacks
It enables the capture and inspection of traffic without impacting network performance
It reduces network bandwidth usage
When you use the internal IP address of the forwarding rule to specify an internal Network Load Balancer next hop, the load balancer can only be:
In the same VPC network as the next hop route or in a peered VPC network
In the same subnet as the next hop route or a Shared VPC network
In the same VPC network as the next hop route
In the same subnet as the next hop route
Where would you configure traffic management for a load balancer?
In the URL map
In the load descriptor
In the load balancer backend
In the load balancer frontend
You can use hybrid load balancing to connect these environments:
Google Cloud and AWS
Google Cloud and on-premises
Google Cloud, AWS, and on-premises
Google Cloud, other public clouds, and on-premises
CDN Interconnect provides:
A private connection between your on-premises network and Google Cloud
A direct connection between your origin servers and Google’s Cloud Load Balancing service
A virtual private network (VPN) tunnel between your VPC network and Google’s global network
A direct peering connection between third-party content delivery networks (CDNs) and Google’s edge network
Which of the following best practices help optimize load balancing cost?
Implementing a caching layer with a content delivery network (CDN)
Selecting the most expensive load balancer type for maximum performance
Ignoring load balancer health checks to avoid additional API calls
Overprovisioning load balancer resources to handle peak traffic loads
When you use the internal IP address of the forwarding rule to specify an internal Network Load Balancer next hop, the load balancer can only be:
In the same subnet as the next hop route or a shared VPC network
In the same VPC network as the next hop route
In the same subnet as the next hop route
In the same VPC network as the next hop route or in a peered VPC network
Your company is located in a city where Google Cloud does not have a Dedicated Interconnect location, but you need a private connection to your Google Cloud Virtual Private Cloud (VPC). Which Cloud Interconnect option is most suitable for this scenario?
Network Connectivity Center
Dedicated Interconnect
Carrier Peering
Partner Interconnect
Which Google Cloud Interconnect option requires the customer to provide their own routing equipment and establish a Border Gateway Protocol (BGP) session with Google’s edge network?
Partner Interconnect
Cross-Cloud Interconnect
Dedicated Interconnect
Network Connectivity Center
In Network Connectivity Center, what are the two main types of spokes that can be connected to a hub?
VPC spokes and Global spokes
Regional spokes and Global spokes
VPC spokes and Hybrid spokes
Global spokes and Hybrid spokes
What is the purpose of a Cloud Router, and why is that important?
To load balance traffic across multiple Google Cloud regions and zones
To filter and restrict traffic based on predefined security rules
To create and manage virtual private networks (VPNs) between on-premises networks and Google Cloud
To dynamically exchange routing information using BGP between Google Cloud VPCs and other networks
Which ONE of the following statements is TRUE concerning Google’s built-in security measures?
Only Google-managed encryption keys are allowed to be used within Google Cloud
Customers always have the option to configure their instances to encrypt all of their data while it is "at rest" within Google Cloud
To guard against phishing attacks, all Google employee accounts require the use of U2F compatible security keys
An organization’s on-premises resources are not allowed to connect to Google Cloud in order to lower the risk of DDoS attacks
Which of the following statements is TRUE regarding Shared Security Responsibility Model in Google Cloud?
Google is responsible for the complete stack including application security and access control
It is a shared responsibility between the customer and Google
The customer is responsible for the complete stack including application security and access control
Which TWO of the following statements are TRUE regarding regulatory compliance on Google Cloud?
Contacting your regulatory compliance certification agency is the only way to find out whether Google currently supports that particular standard
Google’s Cloud products regularly undergo independent verification of security, privacy, and compliance controls
Google has no plans at this time to expand its already-extensive portfolio of regulatory compliance certifications
Proper configuration of encryption and firewalls is not the only requirement for achieving regulatory compliance
For Platform-as-a-Service (PaaS) offerings, which of the following is NOT a customer-managed component of the shared security responsibility model?
Web application security
Network security
Deployment
Access policies
Which of the following statements is TRUE for the use of Cloud Identity?
Cloud Identity can work with any domain name that is able to receive email
You cannot use both Cloud Identity and Google Workspace services to manage your users across your domain
Your organization must use Google Workspace services in order to use Cloud Identity
A Google Workspace or Cloud Identity account can be associated with more than one Organization
The main purpose of Google Cloud Directory Sync is to: (choose ONE)
Help simplify provisioning and de-provisioning user accounts
Enable two-way data synchronization between Google Cloud and AD/LDAP accounts
Completely replace an Active Directory or LDAP service
Bonpoc: Which TWO of the following are considered authentication "best practices"?
Avoid managing permissions on an individual user basis where possible
You should have no more than three Organization admins
Organization Admins should never remove the default Organization-level permissions from users after account creation
Requiring 2-Step Verification (2SV) is only recommended for super-admin accounts
Which THREE of the following are IAM Objects that can be used to organize resources in Google Cloud?
Organization
Member
Folder
Role
Project
Projects in Google Cloud provide many management-related features, including the ability to (choose TWO):
Keep on-prem AD/LDAP accounts synced up with user’s Google Cloud resources
Selectively enable specific services and APIs
Balance server load between different Projects
Track and manage quota usage
Which TWO of the following statements about Cloud IAM Policies is TRUE?
A policy is a collection of access statements attached to a resource
A Policy binding binds a list of members to a role
A less restrictive parent policy will not override a more restrictive child resource policy
An organization policy can only be applied to the organization node
Which TWO of the following statements about VPCs is TRUE?
VPC firewall rules in Google Cloud are global in scope
Every VPC network functions as a distributed firewall where firewall rules are defined at the network level
A connection is considered active if it has at least one packet sent over a one hour period
Google Cloud Firewall allows rules by default only affect traffic flowing in one direction
Which FOUR of the following are firewall rule parameters?
IP Address
Project
Direction
Source
Action
Which ONE of the following statements is TRUE when discussing the SSL capabilities of Google Cloud Load Balancer?
If no SSL policy is set, the SSL policy is automatically set to the most constrained policy, which is RESTRICTED
Google Cloud Load Balancers require, and will only accept, a Google-managed SSL Cert
You must use one of the 3 pre-configured “Google-managed profiles” to specify the level of compatibility appropriate for your application
The Google-managed profile, COMPATIBLE, allows clients which support out-of-date SSL features
Which statement about VPC Service Controls is false?
VPC Service Controls prevent data from being copied to unauthorized resources outside the perimeter using service operations
VPC Service Controls restrict Internet access to resources within a perimeter using allowlisted IPv4 and IPv6 ranges
VPC Service Controls protect resources within a perimeter so they can only be privately accessed from clients within authorized VPC networks
VPC Service Controls restrict Internet access to resources within a perimeter by checking permissions assigned to Cloud Identity and Active Directory accounts only
Bonpoc: Which of the following TWO statements about Google Cloud service accounts are TRUE?
Custom service accounts use "scopes" to control API access
Virtual Machine (VM) instances use service accounts to run API requests on your behalf
Service accounts are a type of identity
VMs without service accounts cannot run APIs
Bonpoc: Which TWO recommendations below ARE considered to be Compute Engine "best practices"?
Hardened custom images are maintained by Google with automatic patches
Utilize projects and IAM roles to control access to your VMs
Cloud Interconnect or Cloud VPN can be used to securely extend your datacenter network into Google Cloud projects
Always run critical VMs with default service accounts
Which TWO of the following statements is TRUE when discussing the Organization Policy Service?
Organization Policy Services allow centralized control for how your organization’s resources can be used
Descendants of a targeted resource do not inherit the parent’s Organization Policy
To define an Organization Policy, you choose a constraint and apply it to a resource
Bonpoc: Which TWO statements about Google Cloud Storage and IAM permissions are TRUE?
Using IAM permissions alone gives you control over your projects, buckets, and individual objects
Using deny rules prevent certain principals from using certain permissions, regardless of the roles they're granted
Access can be granted to Cloud Storage at the organization, folder, project, or bucket levels
A user needs permission from both IAM or an ACL to access a bucket or object
Bonpoc: Which TWO statements are TRUE when discussing storage and BigQuery best practices?
One option to serve content securely to outside users is to use signed URLs
In most cases, you should use Access Control Lists (ACLs) instead of IAM permissions
Do not use any personally identifiable information as object names
BigQuery data can be adequately secured using the default basic roles
Which TWO statements are TRUE regarding security in BigQuery and its datasets?
BigQuery has its own list of assignable IAM roles
A BigQuery Authorized View allows administrators to restrict users to viewing subsets of a dataset
It is always better to assign BigQuery roles to individuals to reduce overhead
Using IAM, you can grant granular permissions to tables, rows, and columns
Bonpoc: Which TWO of the following statements about Application Security are TRUE?
Applications in general, including many web applications, do not properly protect sensitive user data
"Injection Flaws" are the least frequently found application security issue
Applications are the most common target of cyberattack
Which TWO vulnerabilities are scanned for when you use Web Security Scanner?
Mixed content
Outdated or insecure libraries
Insecure logins
User data in images
Personalized data in object names
Which TWO of the following statements are TRUE regarding OAuth and Identity Phishing threats?
Being "hacked" on a social site can lead to being "hacked" on more critical websites
Look-alike phishing sites are generally easy to spot
Credit card data is the only information useful to cyber hackers
Even small, unimportant pieces of personal data must be secured from phishing attacks
"Kubernetes service account" and "Google service account" are different names for the same type of service account.
True
False
Which ONE of the following is NOT a security best practice on Kubernetes.
Upgrade your GKE infrastructure.
Use shielded GKE nodes.
Restrict access between pods.
Disable Workload Identity.
GKE has logging and monitoring functions built in.
True
False
Choose the FOUR correct DDoS Mitigation Layers from the list below.
Load Balancing
Attack Surface
Ping Report
Internal Traffic
CDN Offloading
Choose from the list below which way Google Cloud helps mitigate the risk of DDoS for its customers.
Google Blocklist API is automatically included within each project.
Internal capacity many times that of any traffic load we can anticipate.
Isolation servers are available with no external or internal access.
Google Cloud firewall rules rate limit the number of requests sent to VMs.
Which TWO of the following statements is TRUE about Google Cloud Armor?
Google Cloud Armor enforces access control based on IPv4 and IPv6 addresses or CIDRs.
Google Cloud Armor currently is not compatible with any third-party partner security products.
Google Cloud Armor protection is delivered at the edge of Google’s network.
Google Cloud Armor is a Ransomware defense service.
Which TWO of the following statements are TRUE when speaking about content-related security threats?
Ransomware is a type of malicious software exploit that threatens to publish or perpetually block access to data unless money is paid.
Screenshots or other images that are made public without redaction can trigger a content-related cyber attack threat.
Tracking and unmasking ransomware attackers, via incoming ransom payments, is usually not very difficult with today’s modern banking systems.
Public, user-supplied reviews, images, or videos are considered "safe content" and generally do not require additional security oversight.
Which TWO of the following options are ways that Google Cloud automates for customers the mitigation of many content threats?
Google has global visibility into malicious sites and content, and is able to warn incoming users of suspected malware.
In Google Drive, all files will undergo a malware scan prior to any file download or file sharing attempt.
In Compute Engine, all files are scanned for ransomware type security breaches before uploading.
Bonpoc: Which TWO of the following tools does Google Cloud make available to customers for the mitigation of content-related security threats?
Cloud Data Loss Prevention API
Cloud Natural Language API
Text Redaction API
Clean Data API
Which TWO of the following statements about Cloud Monitoring and Cloud Logging are TRUE?
You can analyze log data in BigQuery.
Cloud Monitoring and Cloud Logging retain logs for an indefinite period of time.
While Cloud Logging is not built-in to most Google Cloud services, you can easily add it for a reasonable fee.
The Cloud Logging Agent can be installed on both Compute Engine and AWS EC2 instances.
Which TWO of the following statements about Cloud Audit Logs are TRUE?
Data Access audit logs record data-access operations on resources that are publicly shared.
Enabling Data Access audit logs might result in your project being charged for the additional logs usage.
Unlike Cloud Logging logs, you cannot export Cloud Audit Logs entries to BigQuery.
Cloud Audit Logs maintains four audit logs for each project, folder, and organization.
Which one of the following statements about Security Command Center is NOT true?
Security Command Center provides a centralized view for cloud resources.
Security Command Center helps you prevent, detect, and respond to threats.
Security Command Center requires three IAM administrative permissions to set up
Security Command Center works by generating “findings” associated with assets.
Which one of the following is NOT a benefit for automating security in Google Cloud environments?
Security automation allows scaling faster than the growth of threats and assets.
Security automation improves consistency, quickness, and reliability.
While beneficial in some situations, the time invested in automating certain tasks is not worth it due to a lack of Google Cloud services that support this framework.
