
50問と120分の制限時間で実際の試験をシミュレーションしましょう。AI検証済み解答と詳細な解説で学習できます。
AI搭載
すべての解答は3つの主要AIモデルで交差検証され、最高の精度を保証します。選択肢ごとの詳細な解説と深い問題分析を提供します。
Your company operates a single Google Cloud organization with 10 folders and 150 projects, and the SOC requires that all Google Cloud Console sign-in events and API calls that change resource configurations be streamed to an external SIEM in under 60 seconds, with coverage for all existing and future projects. Requirements:
You lead network security for a fintech trading platform on Google Cloud. You currently detect anomalies using VPC Flow Logs exported to BigQuery with a 5-minute aggregation interval across three VPCs. A red team exercise now requires examining full packet payloads and L4/L7 headers for east-west traffic between two production subnets (10.20.0.0/24 and 10.20.1.0/24) in a single VPC and forwarding a copy of up to 8 Gbps of this traffic to a third-party NIDS running on a Compute Engine VM, without altering original packets. Which Google Cloud product should you use?
Your company has a three-level resource hierarchy: Organization > Business Unit folders > Team folders, and you are onboarding 12 platform squads that each receive a dedicated Terraform provisioner service account; each squad must be able to create and fully manage projects only under its assigned team folder (for example, folders/789012345678) while adhering to least privilege and preventing project creation in any other location; you need a scalable, centrally managed approach that supports Infrastructure as Code and avoids granting broad administrative control at the folder or organization level; what should you do?
Your retail analytics platform runs on two Compute Engine instances behind a load balancer and authenticates to Google APIs using a user-managed service account key stored in Secret Manager (secret name: retail-sa-key), and your security policy mandates rotation every 90 days with no more than 2 minutes of reduced capacity. To follow Google-recommended practices when rotating this user-managed service account key, what should you do?
Your compliance team is launching an internal meeting-notes summarization pipeline on Google Cloud that uses a generative model to create summaries from audio transcripts, it must process up to 3,000 transcripts per day (average 1 MB each) with under 200 ms filtering latency per request, and company policy mandates that no personally identifiable information (PII)—such as names, email addresses, phone numbers, or government IDs—may appear in either the prompts sent to the model or the summaries returned, so you need a managed, scalable control that detects and automatically redacts PII on both ingress and egress before any storage or display; what should you do?
外出先でもすべての問題を解きたいですか?
Cloud Passを無料でダウンロード — 模擬試験、学習進捗の追跡などを提供します。
Your organization uses a Shared VPC where net-hub-prod is the host project, and all firewall rules, subnets, and an HA VPN with Cloud Router are configured in the host; you need to let the Data Science Blue group attach Compute Engine VMs in service project ml-svc-02 only to the us-central1 subnetwork 172.16.20.0/24 and prevent attachment to any other subnet—what should you grant to the group to meet this requirement?
Your production Google Cloud project runs a managed instance group behind an external HTTP(S) load balancer; a team of 10 release engineers must roll out new application versions by updating instance templates and triggering deployments via Cloud Build, but they must not be able to create, update, or delete any VPC firewall rules in the shared network; only a 2-person NetOps group may change firewall rules, and auditors require least privilege with clear separation of duties and auditable assignments. What should you do?
Your retail chain streams point-of-sale logs every 5 minutes from 300 branches via Pub/Sub into a Dataflow pipeline that writes to Cloud Bigtable for fraud analytics, and you discover that two PII fields (national ID numbers and phone numbers) are included; you must obfuscate these fields during ingestion to prevent analysts from seeing raw values, yet be able to re-identify the original values for regulatory investigations within 7 years while maintaining consistent tokens to enable joins and group-bys; which two components should you use? (Choose two.)
Your company runs 20 CI pipelines in GitHub Actions and Azure DevOps outside Google Cloud that deploy to 8 Google Cloud projects using workload identity federation; service account keys are prohibited by policy. You must prevent attackers from spoofing another pipeline's identity (for example, by manipulating mutable claims like email or display name) to obtain unauthorized access to Google Cloud resources, while keeping existing federation flows and token lifetimes (1 hour) unchanged. What should you do? (Choose two.)
A media analytics company performs a 7-day manual security review for every new service that verifies service-to-service transit paths, request handling, and VPC firewall rules across 3 projects and 2 Shared VPCs. With 12 squads releasing about 25 GKE and Cloud Run services per month, this process delays releases and consumes security bandwidth. They want teams to deploy without the full manual review while ensuring that violations (for example, 0.0.0.0/0 on TCP:22, publicly readable Cloud Storage buckets, or egress to restricted RFC1918 ranges) are prevented before merge/deploy rather than detected in production. They already use GitHub and Cloud Build and cannot fund a dedicated security reviewer per squad. What should you recommend?
学習期間: 2 months
I used Cloud Pass during my last week of study, and it helped reinforce everything from beyondcorp principles to securing workloads. It’s straightforward, easy to use, and genuinely helps you understand security trade-offs.
学習期間: 1 month
문제 다 풀고 시험에 응했는데 바로 합격했어요! 시험이랑 문제는 비슷한게 40% 조금 넘었던거 같고, 처음 보는 유형은 제 개념 이해를 바탕으로 풀었어요.
学習期間: 1 month
I would like to thanks the team of Cloud Pass for these greats materials. This helped me passing the exam last week. Most of the questions in exam as the sample questions and some were almost similar. Thank you again Cloud Pass
学習期間: 1 month
Absolutely invaluable resource to prepare for the exam. Explanations and questions are spot on to give you a sense of what is expected from you on the actual test.
学習期間: 1 month
I realized I was weak in log-based alerts and access boundary configurations. Solving questions here helped me quickly identify and fix those gaps. The question style wasn’t identical to the exam, but the concepts were spot-on.
無料アプリを入手