exam questions

Exam Professional Cloud Security Engineer All Questions

View all questions & answers for the Professional Cloud Security Engineer exam

Exam Professional Cloud Security Engineer topic 1 question 195 discussion

Actual exam question from Google's Professional Cloud Security Engineer
Question #: 195
Topic #: 1
[All Professional Cloud Security Engineer Questions]

You are auditing all your Google Cloud resources in the production project. You want to identify all principals who can change firewall rules.

What should you do?

  • A. Use Policy Analyzer to query the permissions compute.firewalls.get or compute.firewalls.list.
  • B. Use Firewall Insights to understand your firewall rules usage patterns.
  • C. Reference the Security Health Analytics – Firewall Vulnerability Findings in the Security Command Center.
  • D. Use Policy Analyzer to query the permissions compute.firewalls.create or compute.firewalls.update or compute.firewalls.delete.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
dija123
7 months ago
Selected Answer: D
D is correct
upvoted 1 times
...
ArizonaClassics
1 year, 1 month ago
Use Policy Analyzer to query the permissions compute.firewalls.create or compute.firewalls.update or compute.firewalls.delete.
upvoted 1 times
...
cyberpunk21
1 year, 2 months ago
Selected Answer: D
D is the option it's a direct question
upvoted 2 times
...
anshad666
1 year, 2 months ago
Selected Answer: D
Must be D
upvoted 2 times
...
akg001
1 year, 2 months ago
Selected Answer: D
D- To identify all principals who can change firewall rules, you should use Policy Analyzer to query for the permissions related to creating, updating, or deleting firewall rules. These permissions are usually associated with compute.firewalls.create, compute.firewalls.update, and compute.firewalls.delete. By checking which principals have these permissions, you can determine who has the ability to change firewall rules in your Google Cloud project.
upvoted 2 times
...
alkaloid
1 year, 2 months ago
Selected Answer: D
D. You can use the Policy Analyzer to check which resources within your organization a principal has a certain roles or permissions on. To get this information, create a query that includes the principal whose access you want to analyze and one or more permissions or roles that you want to check for. https://cloud.google.com/policy-intelligence/docs/analyze-iam-policies#:~:text=You%20can%20use%20the%20Policy%20Analyzer%20to%20check%20which%20resources,you%20want%20to%20check%20for.
upvoted 2 times
...
K1SMM
1 year, 2 months ago
D is correct!
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago