Your organization hosts a financial services application running on Compute Engine instances for a third- party company. The third-party company's servers that will consume the application also run on Compute Engine in a separate Google Cloud organization. You need to configure a secure network connection between the Compute Engine instances. You have the following requirements:
The network connection must be encrypted.
The communication between servers must be over private IP addresses.
What should you do?
A. Configure an Apigee proxy that exposes your Compute Engine-hosted application as an API, and is encrypted with TLS which allows access only to the third party.
B. Configure a VPC peering connection between your organization's VPC network and the third party's that is controlled by VPC firewall rules.
C. Configure a VPC Service Controls perimeter around your Compute Engine instances, and provide access to the third party via an access level.
D. Configure a Cloud VPN connection between your organization's VPC network and the third party's that is controlled by VPC firewall rules.
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 2:
You are setting up Cloud Identity for your company's Google Cloud organization. User accounts will be provisioned from Microsoft Entra ID through Directory Sync and there will be a single sign-on through Entra ID. You need to secure the super administrator accounts for the organization. Your solution must follow the principle of least privilege and implement strong authentication. What should you do?
A. Create accounts that combine the organization administrator and the super administrator privileges.
Ensure that 2-step verification is enforced for the super administrator accounts in Entra ID.
B. Create accounts that combine the organization administrators and the super administrator privileges.Enforce Google 2-step verification for the super administrator accounts.
C. Create dedicated accounts for super administrators. Enforce Google 2-step verification for the super administrator accounts.
D. Create dedicated accounts for super administrators. Ensure that 2-step verification is enforced for the super administrator accounts in Entra ID.
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 3:
Your company is developing a new application for your organization. The application consists of two Cloud Run services, service A and service B. Service A provides a web-based user front-end. Service B provides back-end services that are called by service A. You need to set up identity and access management for the application. Your solution should follow the principle of least privilege. What should you do?
A. Use the Compute Engine default service account to run service A and service B. Require authentication for service B. Permit only the default service account to call the backend.
B. Create two separate service accounts. Grant one service account the permissions to execute service A, and grant the other service account the permissions to execute service B. Require authentication for service B. Permit only the service account for service A to call the back-end.
C. Create a new service account with the permissions to run service A and service B. Require authentication for service B. Permit only the new service account to call the backend.
D. Create three separate service accounts. Grant one service account the permissions to execute service A.Grant the second service account the permissions to run service B. Grant the third service account the permissions to communicate between both services A and B. Require authentication for service B. Call the back-end by authenticating with a service account key for the third service account.
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
質問 4:
Your organization enforces a custom organization policy that disables the use of Compute Engine VM instances with external IP addresses. However, a regulated business unit requires an exception to temporarily use external IPs for a third-party audit process. The regulated business workload must comply with least privilege principles and minimize policy drift. You need to ensure secure policy management and proper handling. What should you do?
A. Apply the custom organization policy at the organization level to restrict external IPs. Move the regulated business workload to a separate folder. Override the policy at that folder level.
B. Modify the custom organization policy at the organization level to allow external IPs for all projects.Configure VPC firewall rules to restrict egress traffic except for the regulated business workload.
C. Create a folder. Apply the restrictive organization policy for non-regulated business workloads in the folder. Place the regulated business workload in that folder.
D. Create an IAM custom role with permissions to bypass organization policies. Assign the custom role to the regulated business team for the specific project.
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 5:
A manager wants to start retaining security event logs for 2 years while minimizing costs. You write a filter to select the appropriate log entries.
Where should you export the logs?
A. StackDriver logging
B. Cloud Storage buckets
C. Cloud Pub/Sub topics
D. BigQuery datasets
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
質問 6:
You need to create a VPC that enables your security team to control network resources such as firewall rules.
How should you configure the network to allow for separation of duties for network resources?
A. Set up a VPC in a project. Assign the Compute Network Admin role to the security team, and assign the Compute Admin role to the developers.
B. Set up VPC Network Peering, and allow developers to peer their network with a Shared VPC.
C. Set up multiple VPC networks, and set up multi-NIC virtual appliances to connect the networks.
D. Set up a Shared VPC where the security team manages the firewall rules, and share the network with developers via service projects.
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 7:
Your organization wants to be General Data Protection Regulation (GDPR) compliant You want to ensure that your DevOps teams can only create Google Cloud resources in the Europe regions.
What should you do?
A. Use the org policy constraint Google Cloud Platform - Resource Location Restriction" on your Google Cloudorganization node.
B. Use Identity-Aware Proxy (IAP) with Access Context Manager to restrict the location of Google Cloud resources.
C. Use Identity and Access Management (1AM) custom roles to ensure that your DevOps team can only create resources in the Europe regions
D. Use the org policy constraint "Restrict Resource Service Usage'* on your Google Cloud organization node.
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 8:
You recently joined the networking team supporting your company's Google Cloud implementation. You are tasked with familiarizing yourself with the firewall rules configuration and providing recommendations based on your networking and Google Cloud experience. What product should you recommend to detect firewall rules that are overlapped by attributes from other firewall rules with higher or equal priority?
A. VPC Flow Logs
B. Firewall Rules Logging
C. Security Command Center
D. Firewall Insights
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 9:
Your company has been creating users manually in Cloud Identity to provide access to Google Cloud resources. Due to continued growth of the environment, you want to authorize the Google Cloud Directory Sync (GCDS) instance and integrate it with your on-premises LDAP server to onboard hundreds of users.
You are required to:
Replicate user and group lifecycle changes from the on-premises LDAP server in Cloud Identity.
Disable any manually created users in Cloud Identity.
You have already configured the LDAP search attributes to include the users and security groups in scope for Google Cloud. What should you do next to complete this solution?
A. 1. Configure the option to delete domain users not found in LDAP.2. Run GCDS after user and group lifecycle changes.
B. 1. Configure the option to suspend domain users not found in LDAP.2. Set up a recurring GCDS task.
C. 1. Configure the LDAP search attributes to exclude manually created Cloud Identity users not found in LDAP.2. Set up a recurring GCDS task.
D. 1. Configure the LDAP search attributes to exclude manually created Cloud identity users not found in LDAP.2. Run GCDS after user and group lifecycle changes.
正解:B
1111 お客様のコメント
クリック」





春日** -
苦手な分野をしっかりと克服して総合力を身に着けていきたいところです・・・。アプリバージョンダウンロードできるのは、通学通勤時間にも重たい本書を持ち歩かなくても勉強できる。