Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A financial enterprise deploys custom-trained classification models to Vertex AI to predict sensitive loan outcomes. A cloud security engineer is tasked with establishing security controls across the model deployment pipeline and inference serving layer to meet the following requirements:
Which combination of controls should the security engineer implement?
Register models using BigQuery ML remote model references in Vertex AI Model Registry; apply Model Armor response templates to filter raw classification probabilities; and configure standard public endpoints protected exclusively by IAM authentication.
Import models into Vertex AI Model Registry without custom routines; configure Dataflow workers to evaluate ground truth batch predictions continuously; and store model binaries in multi-region Cloud Storage buckets with Object Versioning.
Deploy models to Google Distributed Cloud using the google_ml_integration extension; store credentials in Secret Manager using sm_secret; and rely on database-level transform functions to truncate inference outputs over standard external connections.
Register versions in Vertex AI Model Registry; verify cryptographic hashes or digital signatures of the model artifact before deployment; implement Custom Prediction Routines (CPR) to sanitize prediction outputs and restrict full probability distributions; and deploy the model to Vertex AI private endpoints connected to the VPC.
Register models using BigQuery ML remote model references in Vertex AI Model Registry; apply Model Armor response templates to filter raw classification probabilities; and configure standard public endpoints protected exclusively by IAM authentication.
Import models into Vertex AI Model Registry without custom routines; configure Dataflow workers to evaluate ground truth batch predictions continuously; and store model binaries in multi-region Cloud Storage buckets with Object Versioning.
Deploy models to Google Distributed Cloud using the google_ml_integration extension; store credentials in Secret Manager using sm_secret; and rely on database-level transform functions to truncate inference outputs over standard external connections.
Register versions in Vertex AI Model Registry; verify cryptographic hashes or digital signatures of the model artifact before deployment; implement Custom Prediction Routines (CPR) to sanitize prediction outputs and restrict full probability distributions; and deploy the model to Vertex AI private endpoints connected to the VPC.
This architecture establishes end-to-end model governance, cryptographic provenance verification, API output defenses, and private network perimeter security using native Vertex AI capabilities.
This solution directly addresses data privacy vulnerabilities at the inference tier while enforcing supply-chain integrity controls and private network transport.