Question 86

While migrating your organization's infrastructure to GCP, a large number of users will need to access GCP Console. The Identity Management team already has a well-established way to manage your users and want to keep using your existing Active Directory or LDAP server along with the existing SSO password.
What should you do?
  • Question 87

    A customer needs an alternative to storing their plain text secrets in their source-code management (SCM) system.
    How should the customer achieve this using Google Cloud Platform?
  • Question 88

    Your team uses a service account to authenticate data transfers from a given Compute Engine virtual machine instance of to a specified Cloud Storage bucket. An engineer accidentally deletes the service account, which breaks application functionality. You want to recover the application as quickly as possible without compromising security.
    What should you do?
  • Question 89

    Your team needs to make sure that a Compute Engine instance does not have access to the internet or to any Google APIs or services.
    Which two settings must remain disabled to meet these requirements? (Choose two.)
  • Question 90

    An organization's security and risk management teams are concerned about where their responsibility lies for certain production workloads they are running in Google Cloud Platform (GCP), and where Google's responsibility lies. They are mostly running workloads using Google Cloud's Platform-as-a-Service (PaaS) offerings, including App Engine primarily.
    Which one of these areas in the technology stack would they need to focus on as their primary responsibility when using App Engine?