Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A financial organization is establishing baseline compute and workload security controls on Google Cloud to comply with strict regulatory mandates. The architecture includes workloads running on Compute Engine instances and Google Kubernetes Engine (GKE) clusters.
The regulatory framework requires the following technical safeguards:
Which combination of Google Cloud security controls and configurations should the organization implement to satisfy these compliance requirements?
Enable Artifact Analysis automatic vulnerability scanning; deploy Cloud HSM to store master encryption keys; enforce Workload Identity Federation on GKE; and attach public IPs with default firewall rules.
Configure Customer-Managed Encryption Keys (CMEK) with Cloud KMS across all Persistent Disks; enable VPC Service Controls perimeters; apply GKE Sandbox (gVisor) on all nodes; and configure Cloud Armor edge policies.
Enable Confidential VMs and Confidential GKE Nodes; activate Shielded VM features (Secure Boot, vTPM, and Integrity Monitoring); enforce Binary Authorization deploy policies; and deploy private GKE clusters utilizing Container-Optimized OS (COS).
Implement Google Cloud Armor security policies; deploy Web Security Scanner for automated DAST testing; enable Container Threat Detection in Security Command Center; and utilize standard Ubuntu-based VM images.
Enable Artifact Analysis automatic vulnerability scanning; deploy Cloud HSM to store master encryption keys; enforce Workload Identity Federation on GKE; and attach public IPs with default firewall rules.
Configure Customer-Managed Encryption Keys (CMEK) with Cloud KMS across all Persistent Disks; enable VPC Service Controls perimeters; apply GKE Sandbox (gVisor) on all nodes; and configure Cloud Armor edge policies.
Enable Confidential VMs and Confidential GKE Nodes; activate Shielded VM features (Secure Boot, vTPM, and Integrity Monitoring); enforce Binary Authorization deploy policies; and deploy private GKE clusters utilizing Container-Optimized OS (COS).
This architecture combines Google Cloud's core compute hardening and isolation services: Confidential Computing, Shielded VMs/GKE Nodes, Binary Authorization, and Container-Optimized OS (COS) in a private cluster topology to establish an end-to-end trusted computing and workload isolation baseline.
This solution comprehensively addresses each technical layer—hardware memory encryption, boot-level verification, deployment-time image attestation, and hardened network isolation—without creating architectural gaps or relying on controls limited to data-at-rest.
Implement Google Cloud Armor security policies; deploy Web Security Scanner for automated DAST testing; enable Container Threat Detection in Security Command Center; and utilize standard Ubuntu-based VM images.