Intrigued by the art of cloud architecture? Discover how to design, develop, and manage robust, secure, scalable, and dynamic solutions on Google Cloud as you prepare for the Professional Cloud Architect exam!
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A financial services organization running critical workloads on Google Cloud receives a high-severity Security Command Center threat finding indicating that an unauthorized binary executed on a production Compute Engine virtual machine (VM).
To adhere to operational excellence and incident response frameworks, the team must rapidly mitigate the immediate threat, preserve forensic evidence for root-cause analysis, and restore service operations.
Which sequence of actions should the cloud architect recommend?
Keep the compromised VM running and exposed to allow live system debugging, and assign full administrative permissions to the investigation team.
Immediately delete the compromised VM instance and its attached disks, then redeploy the workload using the latest automated unverified build.
Stop the compromised VM instance, create snapshots of the persistent disks for forensic analysis, deploy a replacement instance from a verified image, and examine Cloud Audit Logs during the post-mortem.
Modify the instance's OS login credentials while leaving the VM running, and disable VPC firewall rules to prevent remote connectivity drops.
Keep the compromised VM running and exposed to allow live system debugging, and assign full administrative permissions to the investigation team.
Immediately delete the compromised VM instance and its attached disks, then redeploy the workload using the latest automated unverified build.
Stop the compromised VM instance, create snapshots of the persistent disks for forensic analysis, deploy a replacement instance from a verified image, and examine Cloud Audit Logs during the post-mortem.
This workflow follows established incident response frameworks and Google Cloud operational excellence principles. It isolates the compromised resource to halt the ongoing threat, captures point-in-time evidence for forensic investigation, restores service availability, and leverages telemetry to analyze root cause during a blameless post-mortem.
This approach cleanly balances security containment, continuous operational availability, and data-driven root cause analysis, preventing future incidents while restoring production systems.
Modify the instance's OS login credentials while leaving the VM running, and disable VPC firewall rules to prevent remote connectivity drops.