Intrigued by the art of cloud architecture? Discover how to design, develop, and manage robust, secure, scalable, and dynamic solutions on Google Cloud as you prepare for the Professional Cloud Architect exam!
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise runs microservices on Google Kubernetes Engine (GKE) and Compute Engine instances. To protect critical assets, the production workloads are enclosed within a VPC Service Controls perimeter. As part of ensuring operational excellence and production reliability, the security team needs to perform automated vulnerability assessments on container images and running workloads without breaking perimeter security or violating the Google Cloud shared responsibility model.
Which configuration should the security team implement?
Disable VPC Service Controls and grant the primitive Owner role to external penetration testing accounts during scheduled assessment windows.
Perform an aggressive Layer 3/4 network flood test directly targeting the underlying Google Cloud physical infrastructure to evaluate network boundary resilience.
Bypass sidecar proxy injection and disable mutual TLS (mTLS) across the service mesh to allow external unauthenticated network scanners to audit internal Pod communication.
Enable Artifact Analysis for container vulnerability scanning and configure VPC Service Controls ingress and egress rules to grant access to the Security Command Center service agent.
Disable VPC Service Controls and grant the primitive Owner role to external penetration testing accounts during scheduled assessment windows.
Perform an aggressive Layer 3/4 network flood test directly targeting the underlying Google Cloud physical infrastructure to evaluate network boundary resilience.
Bypass sidecar proxy injection and disable mutual TLS (mTLS) across the service mesh to allow external unauthenticated network scanners to audit internal Pod communication.
Enable Artifact Analysis for container vulnerability scanning and configure VPC Service Controls ingress and egress rules to grant access to the Security Command Center service agent.
Artifact Analysis and Security Command Center (SCC) Vulnerability Assessment provide comprehensive, automated vulnerability scanning for container images and cloud workloads. Under Google Cloud's shared responsibility model, customers are responsible for securing and auditing their application code, container images, and runtime configurations, while Google secures the underlying physical and hypervisor infrastructure.
Cloud Security Command Center Service Agent allows SCC vulnerability scanners to inspect protected resources without dismantling perimeter controls.This approach aligns with Google Cloud security best practices by enabling continuous, deep vulnerability assessment across containerized workloads while respecting perimeter boundaries established by VPC Service Controls.