Professional Cloud DevOps Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A financial enterprise is establishing a secure cloud development environment on Google Cloud to support sensitive application engineering workloads under strict regulatory compliance. The architecture must satisfy the following security specifications:
Which configuration steps should the DevOps engineer implement?
Provision a Private Service Connect Secure Source Manager instance encrypted with a regional Cloud KMS symmetric key, include the project in a VPC Service Controls service perimeter, and specify Secure Source Manager as a restricted service.
Provision Secure Source Manager with VPC Network Peering across spoke networks, configure client-side token encryption using Secret Manager, and attach an Access Context Manager basic access level that permits all public IP ranges.
Provision a public Secure Source Manager instance with TLS enforcement, enable Cloud KMS asymmetric key encryption at the organization level, and use hierarchical firewall rules to deny external IP ingress.
Deploy a Compute Engine bastion host with an external IP address, configure OS Login with 2-step verification, and assign the Cloud IDS Admin role to developer service accounts.
Provision a Private Service Connect Secure Source Manager instance encrypted with a regional Cloud KMS symmetric key, include the project in a VPC Service Controls service perimeter, and specify Secure Source Manager as a restricted service.
This solution implements an enterprise-grade secure development environment by combining Secure Source Manager, Private Service Connect (PSC), Customer-Managed Encryption Keys (CMEK), and VPC Service Controls (VPC SC).
This architecture directly aligns with Google Cloud security best practices by implementing defense-in-depth across the network, storage, and identity layers.
Provision Secure Source Manager with VPC Network Peering across spoke networks, configure client-side token encryption using Secret Manager, and attach an Access Context Manager basic access level that permits all public IP ranges.
Provision a public Secure Source Manager instance with TLS enforcement, enable Cloud KMS asymmetric key encryption at the organization level, and use hierarchical firewall rules to deny external IP ingress.
Deploy a Compute Engine bastion host with an external IP address, configure OS Login with 2-step verification, and assign the Cloud IDS Admin role to developer service accounts.