wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

gcloud 6-11

Total questions: 52

Worksheet time: 26mins

Name
Class
Date
1.

Which Google Cloud service provides defense against infrastructure and application Distributed Denial of Service (DDoS) attacks?

a)

Google Cloud Armor

b)

Cloud Load Balancing

c)

Cloud DNS

d)

Cloud CDN

2.

Which two of the following statements are true about Google Cloud Armor?

a)

Google Cloud Armor protection is delivered at the edge of Google’s network

b)

Google Cloud Armor is a ransomware defense service

c)

Google Cloud Armor is not currently compatible with any third-party partner security products

d)

Google Cloud Armor enforces access control based on IPv4 and IPv6 addresses or CIDRs

3.

Which IAM role contains permissions to create, modify, and delete networking resources, except for firewall rules and SSL certificates?

a)

Network viewer

b)

Security administrator

c)

Network administrator

d)

Security viewer

4.

Which type of IAM member belongs to an application or virtual machine instead of an individual end user?

a)

Cloud Identity domain

b)

Google group

c)

Service account

d)

Google account

5.

What is the primary purpose of Packet Mirroring in network security?

a)

To redirect traffic to a different network interface

b)

To filter out unwanted traffic from a network

c)

To create a duplicate copy of network traffic for analysis

d)

To encrypt network traffic for privacy

6.

Which of the following is a key benefit of using Packet Mirroring for network security analysis?

a)

It automatically patches vulnerabilities in software

b)

It directly prevents cyberattacks

c)

It enables the capture and inspection of traffic without impacting network performance

d)

It reduces network bandwidth usage

7.

When you use the internal IP address of the forwarding rule to specify an internal Network Load Balancer next hop, the load balancer can only be:

a)

In the same VPC network as the next hop route or in a peered VPC network

b)

In the same subnet as the next hop route or a Shared VPC network

c)

In the same VPC network as the next hop route

d)

In the same subnet as the next hop route

8.

Where would you configure traffic management for a load balancer?

a)

In the URL map

b)

In the load descriptor

c)

In the load balancer backend

d)

In the load balancer frontend

9.

You can use hybrid load balancing to connect these environments:

a)

Google Cloud and AWS

b)

Google Cloud and on-premises

c)

Google Cloud, AWS, and on-premises

d)

Google Cloud, other public clouds, and on-premises

10.

CDN Interconnect provides:

a)

A private connection between your on-premises network and Google Cloud

b)

A direct connection between your origin servers and Google’s Cloud Load Balancing service

c)

A virtual private network (VPN) tunnel between your VPC network and Google’s global network

d)

A direct peering connection between third-party content delivery networks (CDNs) and Google’s edge network

11.

Which of the following best practices help optimize load balancing cost?

a)

Implementing a caching layer with a content delivery network (CDN)

b)

Selecting the most expensive load balancer type for maximum performance

c)

Ignoring load balancer health checks to avoid additional API calls

d)

Overprovisioning load balancer resources to handle peak traffic loads

12.

When you use the internal IP address of the forwarding rule to specify an internal Network Load Balancer next hop, the load balancer can only be:

a)

In the same subnet as the next hop route or a shared VPC network

b)

In the same VPC network as the next hop route

c)

In the same subnet as the next hop route

d)

In the same VPC network as the next hop route or in a peered VPC network

13.

Your company is located in a city where Google Cloud does not have a Dedicated Interconnect location, but you need a private connection to your Google Cloud Virtual Private Cloud (VPC). Which Cloud Interconnect option is most suitable for this scenario?

a)

Network Connectivity Center

b)

Dedicated Interconnect

c)

Carrier Peering

d)

Partner Interconnect

14.

Which Google Cloud Interconnect option requires the customer to provide their own routing equipment and establish a Border Gateway Protocol (BGP) session with Google’s edge network?

a)

Partner Interconnect

b)

Cross-Cloud Interconnect

c)

Dedicated Interconnect

d)

Network Connectivity Center

15.

In Network Connectivity Center, what are the two main types of spokes that can be connected to a hub?

a)

VPC spokes and Global spokes

b)

Regional spokes and Global spokes

c)

VPC spokes and Hybrid spokes

d)

Global spokes and Hybrid spokes

16.

What is the purpose of a Cloud Router, and why is that important?

a)

To load balance traffic across multiple Google Cloud regions and zones

b)

To filter and restrict traffic based on predefined security rules

c)

To create and manage virtual private networks (VPNs) between on-premises networks and Google Cloud

d)

To dynamically exchange routing information using BGP between Google Cloud VPCs and other networks

17.

Which ONE of the following statements is TRUE concerning Google’s built-in security measures?

a)

Only Google-managed encryption keys are allowed to be used within Google Cloud

b)

Customers always have the option to configure their instances to encrypt all of their data while it is "at rest" within Google Cloud

c)

To guard against phishing attacks, all Google employee accounts require the use of U2F compatible security keys

d)

An organization’s on-premises resources are not allowed to connect to Google Cloud in order to lower the risk of DDoS attacks

18.

Which of the following statements is TRUE regarding Shared Security Responsibility Model in Google Cloud?

a)

Google is responsible for the complete stack including application security and access control

b)

It is a shared responsibility between the customer and Google

c)

The customer is responsible for the complete stack including application security and access control

19.

Which TWO of the following statements are TRUE regarding regulatory compliance on Google Cloud?

a)

Contacting your regulatory compliance certification agency is the only way to find out whether Google currently supports that particular standard

b)

Google’s Cloud products regularly undergo independent verification of security, privacy, and compliance controls

c)

Google has no plans at this time to expand its already-extensive portfolio of regulatory compliance certifications

d)

Proper configuration of encryption and firewalls is not the only requirement for achieving regulatory compliance

20.

For Platform-as-a-Service (PaaS) offerings, which of the following is NOT a customer-managed component of the shared security responsibility model?

a)

Web application security

b)

Network security

c)

Deployment

d)

Access policies

21.

Which of the following statements is TRUE for the use of Cloud Identity?

a)

Cloud Identity can work with any domain name that is able to receive email

b)

You cannot use both Cloud Identity and Google Workspace services to manage your users across your domain

c)
  • Your organization must use Google Workspace services in order to use Cloud Identity

d)
  • A Google Workspace or Cloud Identity account can be associated with more than one Organization

22.

The main purpose of Google Cloud Directory Sync is to: (choose ONE)

a)

Help simplify provisioning and de-provisioning user accounts

b)

Enable two-way data synchronization between Google Cloud and AD/LDAP accounts

c)

Completely replace an Active Directory or LDAP service

23.

Bonpoc: Which TWO of the following are considered authentication "best practices"?

a)

Avoid managing permissions on an individual user basis where possible

b)

You should have no more than three Organization admins

c)

Organization Admins should never remove the default Organization-level permissions from users after account creation

d)

Requiring 2-Step Verification (2SV) is only recommended for super-admin accounts

24.

Which THREE of the following are IAM Objects that can be used to organize resources in Google Cloud?

a)

Organization

b)

Member

c)

Folder

d)

Role

e)

Project

25.

Projects in Google Cloud provide many management-related features, including the ability to (choose TWO):

a)

Keep on-prem AD/LDAP accounts synced up with user’s Google Cloud resources

b)

Selectively enable specific services and APIs

c)

Balance server load between different Projects

d)

Track and manage quota usage

26.

Which TWO of the following statements about Cloud IAM Policies is TRUE?

a)

A policy is a collection of access statements attached to a resource

b)

A Policy binding binds a list of members to a role

c)

A less restrictive parent policy will not override a more restrictive child resource policy

d)

An organization policy can only be applied to the organization node

27.

Which TWO of the following statements about VPCs is TRUE?

a)

VPC firewall rules in Google Cloud are global in scope

b)

Every VPC network functions as a distributed firewall where firewall rules are defined at the network level

c)
  • A connection is considered active if it has at least one packet sent over a one hour period

d)
  • Google Cloud Firewall allows rules by default only affect traffic flowing in one direction

28.

Which FOUR of the following are firewall rule parameters?

a)

IP Address

b)

Project

c)

Direction

d)

Source

e)

Action

29.

Which ONE of the following statements is TRUE when discussing the SSL capabilities of Google Cloud Load Balancer?

a)

If no SSL policy is set, the SSL policy is automatically set to the most constrained policy, which is RESTRICTED

b)

Google Cloud Load Balancers require, and will only accept, a Google-managed SSL Cert

c)

You must use one of the 3 pre-configured “Google-managed profiles” to specify the level of compatibility appropriate for your application

d)

The Google-managed profile, COMPATIBLE, allows clients which support out-of-date SSL features

30.

Which statement about VPC Service Controls is false?

a)

VPC Service Controls prevent data from being copied to unauthorized resources outside the perimeter using service operations

b)

VPC Service Controls restrict Internet access to resources within a perimeter using allowlisted IPv4 and IPv6 ranges

c)

VPC Service Controls protect resources within a perimeter so they can only be privately accessed from clients within authorized VPC networks

d)

VPC Service Controls restrict Internet access to resources within a perimeter by checking permissions assigned to Cloud Identity and Active Directory accounts only

31.

Bonpoc: Which of the following TWO statements about Google Cloud service accounts are TRUE?

a)

Custom service accounts use "scopes" to control API access

b)

Virtual Machine (VM) instances use service accounts to run API requests on your behalf

c)

Service accounts are a type of identity

d)

VMs without service accounts cannot run APIs

32.

Bonpoc: Which TWO recommendations below ARE considered to be Compute Engine "best practices"?

a)

Hardened custom images are maintained by Google with automatic patches

b)

Utilize projects and IAM roles to control access to your VMs

c)

Cloud Interconnect or Cloud VPN can be used to securely extend your datacenter network into Google Cloud projects

d)

Always run critical VMs with default service accounts

33.

Which TWO of the following statements is TRUE when discussing the Organization Policy Service?

a)

Organization Policy Services allow centralized control for how your organization’s resources can be used

b)

Descendants of a targeted resource do not inherit the parent’s Organization Policy

c)

To define an Organization Policy, you choose a constraint and apply it to a resource

34.

Bonpoc: Which TWO statements about Google Cloud Storage and IAM permissions are TRUE?

a)

Using IAM permissions alone gives you control over your projects, buckets, and individual objects

b)

Using deny rules prevent certain principals from using certain permissions, regardless of the roles they're granted

c)

Access can be granted to Cloud Storage at the organization, folder, project, or bucket levels

d)

A user needs permission from both IAM or an ACL to access a bucket or object

35.

Bonpoc: Which TWO statements are TRUE when discussing storage and BigQuery best practices?

a)

One option to serve content securely to outside users is to use signed URLs

b)

In most cases, you should use Access Control Lists (ACLs) instead of IAM permissions

c)

Do not use any personally identifiable information as object names

d)

BigQuery data can be adequately secured using the default basic roles

36.

Which TWO statements are TRUE regarding security in BigQuery and its datasets?

a)

BigQuery has its own list of assignable IAM roles

b)

A BigQuery Authorized View allows administrators to restrict users to viewing subsets of a dataset

c)

It is always better to assign BigQuery roles to individuals to reduce overhead

d)

Using IAM, you can grant granular permissions to tables, rows, and columns

37.

Bonpoc: Which TWO of the following statements about Application Security are TRUE?

a)

Applications in general, including many web applications, do not properly protect sensitive user data

b)

"Injection Flaws" are the least frequently found application security issue

c)

Applications are the most common target of cyberattack

38.

Which TWO vulnerabilities are scanned for when you use Web Security Scanner?

a)

Mixed content

b)

Outdated or insecure libraries

c)

Insecure logins

d)

User data in images

e)

Personalized data in object names

39.

Which TWO of the following statements are TRUE regarding OAuth and Identity Phishing threats?

a)

Being "hacked" on a social site can lead to being "hacked" on more critical websites

b)

Look-alike phishing sites are generally easy to spot

c)

Credit card data is the only information useful to cyber hackers

d)

Even small, unimportant pieces of personal data must be secured from phishing attacks

40.

"Kubernetes service account" and "Google service account" are different names for the same type of service account.

a)

True

b)

False

41.

Which ONE of the following is NOT a security best practice on Kubernetes.

a)

Upgrade your GKE infrastructure.

b)

Use shielded GKE nodes.

c)

Restrict access between pods.

d)

Disable Workload Identity.

42.

GKE has logging and monitoring functions built in.

a)

True

b)

False

43.

Choose the FOUR correct DDoS Mitigation Layers from the list below.

a)

Load Balancing

b)

Attack Surface

c)

Ping Report

d)

Internal Traffic

e)

CDN Offloading

44.

Choose from the list below which way Google Cloud helps mitigate the risk of DDoS for its customers.

a)

Google Blocklist API is automatically included within each project.

b)

Internal capacity many times that of any traffic load we can anticipate.

c)

Isolation servers are available with no external or internal access.

d)

Google Cloud firewall rules rate limit the number of requests sent to VMs.

45.

Which TWO of the following statements is TRUE about Google Cloud Armor?

a)

Google Cloud Armor enforces access control based on IPv4 and IPv6 addresses or CIDRs.

b)

Google Cloud Armor currently is not compatible with any third-party partner security products.

c)

Google Cloud Armor protection is delivered at the edge of Google’s network.

d)

Google Cloud Armor is a Ransomware defense service.

46.

Which TWO of the following statements are TRUE when speaking about content-related security threats?

a)

Ransomware is a type of malicious software exploit that threatens to publish or perpetually block access to data unless money is paid.

b)

Screenshots or other images that are made public without redaction can trigger a content-related cyber attack threat.

c)

Tracking and unmasking ransomware attackers, via incoming ransom payments, is usually not very difficult with today’s modern banking systems.

d)

Public, user-supplied reviews, images, or videos are considered "safe content" and generally do not require additional security oversight.

47.

Which TWO of the following options are ways that Google Cloud automates for customers the mitigation of many content threats?

a)

Google has global visibility into malicious sites and content, and is able to warn incoming users of suspected malware.

b)

In Google Drive, all files will undergo a malware scan prior to any file download or file sharing attempt.

c)

In Compute Engine, all files are scanned for ransomware type security breaches before uploading.

48.

Bonpoc: Which TWO of the following tools does Google Cloud make available to customers for the mitigation of content-related security threats?

a)

Cloud Data Loss Prevention API

b)

Cloud Natural Language API

c)

Text Redaction API

d)

Clean Data API

49.

Which TWO of the following statements about Cloud Monitoring and Cloud Logging are TRUE?

a)

You can analyze log data in BigQuery.

b)

Cloud Monitoring and Cloud Logging retain logs for an indefinite period of time.

c)

While Cloud Logging is not built-in to most Google Cloud services, you can easily add it for a reasonable fee.

d)

The Cloud Logging Agent can be installed on both Compute Engine and AWS EC2 instances.

50.

Which TWO of the following statements about Cloud Audit Logs are TRUE?

a)

Data Access audit logs record data-access operations on resources that are publicly shared.

b)

Enabling Data Access audit logs might result in your project being charged for the additional logs usage.

c)

Unlike Cloud Logging logs, you cannot export Cloud Audit Logs entries to BigQuery.

d)

Cloud Audit Logs maintains four audit logs for each project, folder, and organization.

51.

Which one of the following statements about Security Command Center is NOT true?

a)

Security Command Center provides a centralized view for cloud resources.

b)

Security Command Center helps you prevent, detect, and respond to threats.

c)

Security Command Center requires three IAM administrative permissions to set up

d)

Security Command Center works by generating “findings” associated with assets.

52.

Which one of the following is NOT a benefit for automating security in Google Cloud environments?

a)

Security automation allows scaling faster than the growth of threats and assets.

b)

Security automation improves consistency, quickness, and reliability.

c)

While beneficial in some situations, the time invested in automating certain tasks is not worth it due to a lack of Google Cloud services that support this framework.