Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A security engineer is configuring end-to-end encryption in transit between application microservices and a Google Cloud SQL for PostgreSQL database instance. The database instance is provisioned using a shared Certificate Authority (shared CA) mode and is accessed over Private Service Connect (PSC).
To satisfy strict compliance and zero-trust policies, client connections must enforce complete cryptographic server identity verification to prevent spoofing and Man-in-the-Middle (MitM) attacks.
Which configuration should the security engineer implement?
Retrieve the instance DNS name from Cloud SQL, create a DNS record for it in a VPC private Cloud DNS zone, and configure the database client to connect to that DNS name using sslmode=verify-full.
Configure the database client to connect directly to the Private Service Connect endpoint's internal IP address with sslmode=verify-full.
Configure a Cloud KMS Customer-Managed Encryption Key (CMEK) to sign database sessions and set the client to sslmode=require.
Connect directly to the Private Service Connect IP address and set the PostgreSQL client connection parameter to sslmode=verify-ca.
Retrieve the instance DNS name from Cloud SQL, create a DNS record for it in a VPC private Cloud DNS zone, and configure the database client to connect to that DNS name using sslmode=verify-full.
Server identity verification with TLS ensures that the client not only validates that the database server's certificate was signed by a trusted Certificate Authority (CA), but also validates that the certificate's Subject Alternative Name (SAN) matches the exact hostname to which the client is connecting.
INSTANCE_UID.PROJECT_DNS_LABEL.REGION_NAME.sql.goog.) in the server certificate's SAN field. Registering this name in a VPC private Cloud DNS zone ensures that private clients correctly resolve the DNS name to the PSC endpoint IP.sslmode=verify-full in PostgreSQL client drivers enforces both trusted CA validation and strict SAN hostname matching.This solution properly aligns DNS resolution, certificate SAN metadata, and client TLS enforcement (sslmode=verify-full), providing end-to-end cryptographic trust.
Configure the database client to connect directly to the Private Service Connect endpoint's internal IP address with sslmode=verify-full.
Configure a Cloud KMS Customer-Managed Encryption Key (CMEK) to sign database sessions and set the client to sslmode=require.
Connect directly to the Private Service Connect IP address and set the PostgreSQL client connection parameter to sslmode=verify-ca.