Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise organization is enhancing its privileged access governance across its Google Cloud infrastructure. The security engineering team must establish a zero-trust, layered defense model for administrators managing production workloads.
The design must satisfy the following security and compliance requirements:
Which combination of Google Cloud services and configurations should the security engineer implement to achieve this layered defense strategy?
Implement App Lifecycle Manager actuation service accounts with OAuth 2.0 token issuance, configure Cloud NAT for internal administrative VM routing, and inspect network logs in Security Command Center using Event Threat Detection.
Configure Privileged Access Manager (PAM) entitlements with approval workflows and IAM condition bindings using Access Context Manager levels; enforce access to administrative endpoints using Identity-Aware Proxy (IAP); and route PAM and IAM Admin Activity audit logs to Cloud Logging and Security Command Center.
Create custom IAM roles with temporary session tags, configure VPC Service Controls perimeter bridges to secure administrative VM access, and export VPC Flow Logs to Cloud Logging to detect unauthorized privilege escalation.
Assign permanent Basic IAM roles with IAM deny policies, deploy an external Application Load Balancer with Cloud Armor WAF rules to proxy VM access, and configure Cloud Trace to audit administrative elevation events.
Implement App Lifecycle Manager actuation service accounts with OAuth 2.0 token issuance, configure Cloud NAT for internal administrative VM routing, and inspect network logs in Security Command Center using Event Threat Detection.
Configure Privileged Access Manager (PAM) entitlements with approval workflows and IAM condition bindings using Access Context Manager levels; enforce access to administrative endpoints using Identity-Aware Proxy (IAP); and route PAM and IAM Admin Activity audit logs to Cloud Logging and Security Command Center.
Privileged Access Manager (PAM) is a Google Cloud security service designed to automate just-in-time (JIT) and time-bound privilege escalation. It natively integrates with Cloud IAM, Access Context Manager (ACM), Identity-Aware Proxy (IAP), and Cloud Logging to create a zero-trust, multi-layered defense architecture.
This architecture directly addresses every layer of defense—identity governance, access boundaries, endpoint exposure reduction, and continuous monitoring—without requiring third-party agents or unmanaged operational overhead.
Create custom IAM roles with temporary session tags, configure VPC Service Controls perimeter bridges to secure administrative VM access, and export VPC Flow Logs to Cloud Logging to detect unauthorized privilege escalation.
Assign permanent Basic IAM roles with IAM deny policies, deploy an external Application Load Balancer with Cloud Armor WAF rules to proxy VM access, and configure Cloud Trace to audit administrative elevation events.