
Simulez l'expérience réelle de l'examen avec 50 questions et une limite de temps de 120 minutes. Entraînez-vous avec des réponses vérifiées par IA et des explications détaillées.
Propulsé par l'IA
Chaque réponse est vérifiée par 3 modèles d'IA de pointe pour garantir une précision maximale. Obtenez des explications détaillées par option et une analyse approfondie des questions.
Your company operates a single Google Cloud organization with 10 folders and 150 projects, and the SOC requires that all Google Cloud Console sign-in events and API calls that change resource configurations be streamed to an external SIEM in under 60 seconds, with coverage for all existing and future projects. Requirements:
You lead network security for a fintech trading platform on Google Cloud. You currently detect anomalies using VPC Flow Logs exported to BigQuery with a 5-minute aggregation interval across three VPCs. A red team exercise now requires examining full packet payloads and L4/L7 headers for east-west traffic between two production subnets (10.20.0.0/24 and 10.20.1.0/24) in a single VPC and forwarding a copy of up to 8 Gbps of this traffic to a third-party NIDS running on a Compute Engine VM, without altering original packets. Which Google Cloud product should you use?
Your company has a three-level resource hierarchy: Organization > Business Unit folders > Team folders, and you are onboarding 12 platform squads that each receive a dedicated Terraform provisioner service account; each squad must be able to create and fully manage projects only under its assigned team folder (for example, folders/789012345678) while adhering to least privilege and preventing project creation in any other location; you need a scalable, centrally managed approach that supports Infrastructure as Code and avoids granting broad administrative control at the folder or organization level; what should you do?
Your retail analytics platform runs on two Compute Engine instances behind a load balancer and authenticates to Google APIs using a user-managed service account key stored in Secret Manager (secret name: retail-sa-key), and your security policy mandates rotation every 90 days with no more than 2 minutes of reduced capacity. To follow Google-recommended practices when rotating this user-managed service account key, what should you do?
Your compliance team is launching an internal meeting-notes summarization pipeline on Google Cloud that uses a generative model to create summaries from audio transcripts, it must process up to 3,000 transcripts per day (average 1 MB each) with under 200 ms filtering latency per request, and company policy mandates that no personally identifiable information (PII)—such as names, email addresses, phone numbers, or government IDs—may appear in either the prompts sent to the model or the summaries returned, so you need a managed, scalable control that detects and automatically redacts PII on both ingress and egress before any storage or display; what should you do?
Envie de vous entraîner partout ?
Téléchargez Cloud Pass gratuitement — inclut des tests d'entraînement, le suivi de progression et plus encore.
Your organization uses a Shared VPC where net-hub-prod is the host project, and all firewall rules, subnets, and an HA VPN with Cloud Router are configured in the host; you need to let the Data Science Blue group attach Compute Engine VMs in service project ml-svc-02 only to the us-central1 subnetwork 172.16.20.0/24 and prevent attachment to any other subnet—what should you grant to the group to meet this requirement?
Your production Google Cloud project runs a managed instance group behind an external HTTP(S) load balancer; a team of 10 release engineers must roll out new application versions by updating instance templates and triggering deployments via Cloud Build, but they must not be able to create, update, or delete any VPC firewall rules in the shared network; only a 2-person NetOps group may change firewall rules, and auditors require least privilege with clear separation of duties and auditable assignments. What should you do?
Your retail chain streams point-of-sale logs every 5 minutes from 300 branches via Pub/Sub into a Dataflow pipeline that writes to Cloud Bigtable for fraud analytics, and you discover that two PII fields (national ID numbers and phone numbers) are included; you must obfuscate these fields during ingestion to prevent analysts from seeing raw values, yet be able to re-identify the original values for regulatory investigations within 7 years while maintaining consistent tokens to enable joins and group-bys; which two components should you use? (Choose two.)
Your company runs 20 CI pipelines in GitHub Actions and Azure DevOps outside Google Cloud that deploy to 8 Google Cloud projects using workload identity federation; service account keys are prohibited by policy. You must prevent attackers from spoofing another pipeline's identity (for example, by manipulating mutable claims like email or display name) to obtain unauthorized access to Google Cloud resources, while keeping existing federation flows and token lifetimes (1 hour) unchanged. What should you do? (Choose two.)
A media analytics company performs a 7-day manual security review for every new service that verifies service-to-service transit paths, request handling, and VPC firewall rules across 3 projects and 2 Shared VPCs. With 12 squads releasing about 25 GKE and Cloud Run services per month, this process delays releases and consumes security bandwidth. They want teams to deploy without the full manual review while ensuring that violations (for example, 0.0.0.0/0 on TCP:22, publicly readable Cloud Storage buckets, or egress to restricted RFC1918 ranges) are prevented before merge/deploy rather than detected in production. They already use GitHub and Cloud Build and cannot fund a dedicated security reviewer per squad. What should you recommend?
Période de préparation: 2 months
I used Cloud Pass during my last week of study, and it helped reinforce everything from beyondcorp principles to securing workloads. It’s straightforward, easy to use, and genuinely helps you understand security trade-offs.
Période de préparation: 1 month
문제 다 풀고 시험에 응했는데 바로 합격했어요! 시험이랑 문제는 비슷한게 40% 조금 넘었던거 같고, 처음 보는 유형은 제 개념 이해를 바탕으로 풀었어요.
Période de préparation: 1 month
I would like to thanks the team of Cloud Pass for these greats materials. This helped me passing the exam last week. Most of the questions in exam as the sample questions and some were almost similar. Thank you again Cloud Pass
Période de préparation: 1 month
Absolutely invaluable resource to prepare for the exam. Explanations and questions are spot on to give you a sense of what is expected from you on the actual test.
Période de préparation: 1 month
I realized I was weak in log-based alerts and access boundary configurations. Solving questions here helped me quickly identify and fix those gaps. The question style wasn’t identical to the exam, but the concepts were spot-on.
Obtenir l'application gratuite