Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise runs critical multi-tier applications across a fleet of standalone Compute Engine virtual machines (VMs) located across multiple zones. The security and infrastructure teams need to implement an automated patch management strategy that meets the following operational and security requirements:
Which solution should the security engineer implement using Google Cloud native services?
Configure Managed Instance Group (MIG) rolling updates with an opportunistic update policy, attaching an application-based autohealing health check to automatically reboot and patch the standalone instances.
Trigger Cloud Functions via Cloud Scheduler to run gcloud compute instances perform-maintenance concurrently across all zones, utilizing Cloud SQL maintenance windows to manage VM reboots.
Create a recurring Patch Deployment in VM Manager with a 2-hour duration, configure the rollout options to patch one zone at a time with a 20% disruption budget, and specify pre-patch and post-patch scripts located in a Cloud Storage bucket accessed by the VM service accounts.
Execute an immediate, on-demand Patch Job with an instance filter targeting all instances across the project (--instance-filter-all), specifying pre-patch and post-patch scripts stored locally in the root directory of each VM.
Configure Managed Instance Group (MIG) rolling updates with an opportunistic update policy, attaching an application-based autohealing health check to automatically reboot and patch the standalone instances.
Trigger Cloud Functions via Cloud Scheduler to run gcloud compute instances perform-maintenance concurrently across all zones, utilizing Cloud SQL maintenance windows to manage VM reboots.
Create a recurring Patch Deployment in VM Manager with a 2-hour duration, configure the rollout options to patch one zone at a time with a 20% disruption budget, and specify pre-patch and post-patch scripts located in a Cloud Storage bucket accessed by the VM service accounts.
VM Manager Patch Deployment is a Google Cloud native service within Compute Engine designed to automate and orchestrate operating system updates across fleets of Linux and Windows virtual machines. It allows administrators to define automated patch schedules, maintenance windows, targeting filters, update categories, and custom scripting lifecycle hooks.
20%). This limits the concurrent number of VMs undergoing updates in any active zone, preserving application capacity and eliminating fleet-wide downtime.Using native VM Manager Patch Deployments provides complete control over scheduled maintenance windows, progressive zonal rollouts, disruption thresholds, and script execution without requiring third-party configuration tools or custom orchestrators.
Execute an immediate, on-demand Patch Job with an instance filter targeting all instances across the project (--instance-filter-all), specifying pre-patch and post-patch scripts stored locally in the root directory of each VM.