Question 106

You are part of a security team investigating a compromised service account key. You need to audit which new resources were created by the service account.
What should you do?
  • Question 107

    You recently joined the networking team supporting your company's Google Cloud implementation. You are tasked with familiarizing yourself with the firewall rules configuration and providing recommendations based on your networking and Google Cloud experience. What product should you recommend to detect firewall rules that are overlapped by attributes from other firewall rules with higher or equal priority?
  • Question 108

    Your organization acquired a new workload. The Web and Application (App) servers will be running on Compute Engine in a newly created custom VPC. You are responsible for configuring a secure network communication solution that meets the following requirements:
    Only allows communication between the Web and App tiers.
    Enforces consistent network security when autoscaling the Web and App tiers.
    Prevents Compute Engine Instance Admins from altering network traffic.
    What should you do?
  • Question 109

    A website design company recently migrated all customer sites to App Engine. Some sites are still in progress and should only be visible to customers and company employees from any location.
    Which solution will restrict access to the in-progress sites?
  • Question 110

    You need to set up two network segments: one with an untrusted subnet and the other with a trusted subnet. You want to configure a virtual appliance such as a next-generation firewall (NGFW) to inspect all traffic between the two network segments. How should you design the network to inspect the traffic?