Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A security architect at an enterprise organization is conducting a compliance assessment to map operational and security obligations across various Google Cloud compute delivery models:
The compliance auditor requires explicit documentation detailing which entity manages node operating system (OS) patching, runtime execution environments, container image security, and customer data protection across each deployment architecture.
Which statement accurately describes the demarcation of responsibilities under the Google Cloud shared responsibility model?
On Compute Engine and GKE Standard, Google automatically patches and maintains the host operating system; on Cloud Run and GKE Autopilot, the customer must manually patch runtime dependencies and manage physical host security, while Google manages application data classification.
GKE Autopilot and Cloud Run eliminate all customer security responsibilities—including application vulnerability management, container access controls, and data protection—by transferring total end-to-end compliance accountability to Google.
On Compute Engine, the customer is responsible for guest OS patching and runtime configurations; on GKE Standard, the customer manages node configuration and initiates or configures node OS upgrades; on GKE Autopilot and Cloud Run, Google manages the underlying node OS patching and runtime infrastructure; across all models, the customer retains responsibility for application code, container contents, and data protection.
Across all compute delivery models (IaaS, PaaS, and managed containers), Google is responsible for OS patching, middleware installation, and firewall rule configurations, whereas the customer is solely responsible for physical security and hardware asset disposal.
On Compute Engine and GKE Standard, Google automatically patches and maintains the host operating system; on Cloud Run and GKE Autopilot, the customer must manually patch runtime dependencies and manage physical host security, while Google manages application data classification.
GKE Autopilot and Cloud Run eliminate all customer security responsibilities—including application vulnerability management, container access controls, and data protection—by transferring total end-to-end compliance accountability to Google.
On Compute Engine, the customer is responsible for guest OS patching and runtime configurations; on GKE Standard, the customer manages node configuration and initiates or configures node OS upgrades; on GKE Autopilot and Cloud Run, Google manages the underlying node OS patching and runtime infrastructure; across all models, the customer retains responsibility for application code, container contents, and data protection.
The Google Cloud shared responsibility model defines the distinct division of security, operational, and compliance obligations between Google Cloud (the cloud service provider) and the customer. As organizations transition from Infrastructure as a Service (IaaS) to Platform as a Service (PaaS) and fully managed container environments, Google assumes greater operational responsibility for lower-level infrastructure, operating systems, and virtualization layers.
This mapping correctly reflects the exact boundaries of operational control across compute architectures. It ensures that internal compliance teams accurately assign operational patch management tasks without creating security blind spots.
Across all compute delivery models (IaaS, PaaS, and managed containers), Google is responsible for OS patching, middleware installation, and firewall rule configurations, whereas the customer is solely responsible for physical security and hardware asset disposal.