Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise is deploying a secure machine learning environment on Google Cloud using Vertex AI Workbench notebooks, Vertex AI Pipelines, and custom training jobs. The workloads process confidential corporate data and proprietary algorithms.
Security and compliance requirements dictate:
Which architectural approach satisfies all of these security requirements?
This architecture establishes a comprehensive defense-in-depth model for PaaS machine learning on Google Cloud. It combines VPC Service Controls (VPC SC) perimeters to enforce strict data boundary controls, Private Service Connect (PSC) endpoints for private API transport, and Customer-Managed Encryption Keys (CMEK) for centralized cryptographic ownership over all machine learning data assets.
aiplatform.googleapis.com, storage.googleapis.com, and cloudkms.googleapis.com prevents unauthorized access or data exfiltration from unauthorized networks, even if credentials are compromised or IAM permissions are misconfigured.This approach directly aligns with Google Cloud enterprise security best practices for generative AI and machine learning platforms. It provides automated boundary enforcement, complete data-at-rest encryption control, and fully private network connectivity.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.