
50개 문제와 120분 시간 제한으로 실제 시험을 시뮬레이션하세요. AI 검증 답안과 상세 해설로 학습하세요.
AI 기반
모든 답안은 3개의 최고 AI 모델로 교차 검증하여 최고의 정확도를 보장합니다. 선택지별 상세 해설과 심층 문제 분석을 제공합니다.
Your marketing analytics unit (120 users) plans to adopt Google Cloud for BigQuery and Vertex AI within 30 days, and company policy requires that all identities remain company-owned and all sign-ins use the corporate SAML 2.0 IdP; while attempting to create a new Cloud Identity tenant for example.com, the Platform Engineer discovers that example.com is already verified and actively used by an internal Google Workspace deployment with 850 active accounts and existing SAML SSO, and needs guidance on how to proceed with the least disruption and without violating the policy. What should you advise?
Your company operates eight autonomous product studios, each with approximately 3,000 users and contractors, and about 1,200 Google Cloud projects distributed across those studios. You must delegate access control administration with the following requirements: ✑ Each studio must administer access only for its own projects and not see or change other studios' projects. ✑ Access must be manageable at scale across hundreds of projects per studio. ✑ When a user transfers to a different studio or leaves the company, their access must be removed within 1 hour. ✑ The authoritative source for users and groups is the on-premises Active Directory, and Google accounts are in Cloud Identity. What should you do? (Choose two.)
A team operates 60 Compute Engine VMs in a managed instance group that must securely read database passwords and third‑party API tokens both at boot and on demand; security policy requires centrally stored secrets with per‑secret IAM controls, access over TLS, versioning and rotation every 90 days, audit logs for every read, optional CMEK support, and a prohibition on storing secrets in instance metadata or guest attributes—what should you recommend?
Your security team just created a custom-mode VPC named seg-west (10.30.0.0/16) with one subnet us-west1-prim (10.30.10.0/24) and intentionally no user-defined firewall rules; a VM named gw-01 in that subnet has an ephemeral external IP, and the team tests: (1) from gw-01, curl https://8.8.8.8:443, (2) from the public internet, attempt SSH (TCP/22) and HTTP (TCP/80) to gw-01, and (3) attempt SMTP egress on TCP/25 from gw-01; which two behaviors are guaranteed solely by Google Cloud's implied VPC firewall rules before any custom rules are added? (Choose two.)
Your video analytics platform operates 400 Compute Engine VMs across 12 projects in us-central1, europe-west1, and asia-southeast1. Rapid hiring has caused base image drift, inconsistent CIS-level hardening, and missed critical OS patches. Security requires that: (1) all new instances launch only from organization-approved hardened images; (2) critical OS patches are applied within 48 hours across all projects; and (3) baseline controls remain enforced throughout each VM's lifecycle. You need a centrally managed approach to standardize images and automate enforcement from provisioning through ongoing operations. What should you do?
이동 중에도 모든 문제를 풀고 싶으신가요?
Cloud Pass를 무료로 다운로드하세요 — 모의고사, 학습 진도 추적 등을 제공합니다.
In a fintech company's Google Cloud environment, the SOC needs the on-premises SIEM to ingest only Compute Engine Admin Activity audit logs and VPC Flow Logs from two projects (proj-sec-01 and proj-sec-02). Access must be read-only, limited to the most recent 30 days, and must not require creating or distributing any long-lived service account keys. Your enterprise IdP is SAML 2.0 and supports OIDC via workforce identity federation; the SIEM can call Google Cloud APIs using short-lived OIDC tokens. You want to minimize data exposure in Google Cloud and avoid copying all logs to external systems. What should you do?
Your team is rolling out a global event-ticketing web front end that peaks at 10,000 requests per second across us-central1, europe-west1, and asia-southeast1; to block XSS/SQLi and abusive IP ranges before traffic hits your services, you plan to enforce Google Cloud Armor WAF and rate limiting at the edge—what two infrastructure prerequisites must be in place for the Cloud Armor security policy to actually evaluate and filter requests? (Choose two.)
You manage security for a media analytics firm hosting 3 internal web dashboards (2 on Cloud Run and 1 on a managed instance group behind a global external HTTP(S) Load Balancer) that must be reachable over the public internet but only by 500 employees in your Google Workspace domain; you need to enforce per-user and group-based access with OAuth 2.0 sign-in, optionally apply device-based restrictions via Access Context Manager, avoid using client VPNs or custom reverse proxies, and capture detailed access audit logs in Cloud Logging. Which Google Cloud service should you use to centrally enforce authentication and fine-grained access control for these applications?
Your security team plans to roll out VPC Service Controls across 12 production projects organized into 4 service perimeters and wants a 14-day evaluation period to test perimeter rule changes and observe potential violations in logs without interrupting any existing access paths (including BigQuery and Cloud Storage requests from on-prem via Private Service Connect). Which VPC Service Controls mode should you use to validate the impact safely while ensuring no requests are blocked during the evaluation window?
You are launching a payment reconciliation service on Cloud Run in asia-southeast1. A regulatory requirement mandates that application logs be retained for 10 years and that all log data remain within Singapore (asia-southeast1) at all times. The service emits approximately 40 GB of logs per day, and your team wants a low-overhead, cost-effective, Google-managed approach. What should you do?
학습 기간: 2 months
I used Cloud Pass during my last week of study, and it helped reinforce everything from beyondcorp principles to securing workloads. It’s straightforward, easy to use, and genuinely helps you understand security trade-offs.
학습 기간: 1 month
문제 다 풀고 시험에 응했는데 바로 합격했어요! 시험이랑 문제는 비슷한게 40% 조금 넘었던거 같고, 처음 보는 유형은 제 개념 이해를 바탕으로 풀었어요.
학습 기간: 1 month
I would like to thanks the team of Cloud Pass for these greats materials. This helped me passing the exam last week. Most of the questions in exam as the sample questions and some were almost similar. Thank you again Cloud Pass
학습 기간: 1 month
Absolutely invaluable resource to prepare for the exam. Explanations and questions are spot on to give you a sense of what is expected from you on the actual test.
학습 기간: 1 month
I realized I was weak in log-based alerts and access boundary configurations. Solving questions here helped me quickly identify and fix those gaps. The question style wasn’t identical to the exam, but the concepts were spot-on.
무료 앱 받기