exam questions

Exam Professional Cloud Security Engineer All Questions

View all questions & answers for the Professional Cloud Security Engineer exam

Exam Professional Cloud Security Engineer topic 1 question 224 discussion

Actual exam question from Google's Professional Cloud Security Engineer
Question #: 224
Topic #: 1
[All Professional Cloud Security Engineer Questions]

You have numerous private virtual machines on Google Cloud. You occasionally need to manage the servers through Secure Socket Shell (SSH) from a remote location. You want to configure remote access to the servers in a manner that optimizes security and cost efficiency.

What should you do?

  • A. Create a site-to-site VPN from your corporate network to Google Cloud.
  • B. Configure server instances with public IP addresses. Create a firewall rule to only allow traffic from your corporate IPs.
  • C. Create a firewall rule to allow access from the Identity-Aware Proxy (IAP) IP range. Grant the role of an IAP-secured Tunnel User to the administrators.
  • D. Create a jump host instance with public IP. Manage the instances by connecting through the jump host.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Pime13
4 months, 2 weeks ago
Selected Answer: C
C - https://cloud.google.com/iap#section-2
upvoted 1 times
...
MMNB2023
5 months, 1 week ago
Selected Answer: C
Using IAP is more secure and cost effective than Bastion VM (VM cost+ maintenace). Specially IAP is a managed security solution.
upvoted 1 times
...
ArizonaClassics
7 months, 2 weeks ago
C. Create a firewall rule to allow access from the Identity-Aware Proxy (IAP) IP range. Grant the role of an IAP-secured Tunnel User to the administrators. Google's Identity-Aware Proxy allows you to establish a secure and context-aware access to your VMs without using a traditional VPN. It's a cost-efficient and secure method, especially for occasional access. You can enforce identity and context-aware access controls, ensuring only authorized users can SSH into the VMs.
upvoted 1 times
...
anshad666
8 months ago
Selected Answer: C
Typical use case for IAP
upvoted 3 times
...
cyberpunk21
8 months, 1 week ago
Selected Answer: A
I think only option A is cost effective. so, I choose option A
upvoted 1 times
...
Mithung30
8 months, 4 weeks ago
C. Create a firewall rule to allow access from the Identity-Aware Proxy (IAP) IP range. Grant the role of an IAP-secured Tunnel User to the administrators. This is a good option for organizations that want to use IAP to secure their remote access. IAP is a Google-managed service that provides a secure way to access Google Cloud resources from the internet. D. Create a jump host instance with public IP. Manage the instances by connecting through the jump host. This is a good option for organizations that want to have a secure way to manage their VMs without exposing them to the public internet. The jump host is a server that is exposed to the public internet and has access to the VMs. Administrators can connect to the jump host and then use it to manage the VMs. In this case, the best option is to create a jump host instance with public IP. This will allow administrators to manage the VMs securely without exposing them to the public internet. The jump host can be configured with a firewall rule to only allow traffic from trusted IP addresses. This will help to protect the VMs from unauthorized access.
upvoted 1 times
...
alkaloid
8 months, 4 weeks ago
Selected Answer: C
C - correct. With TCP forwarding, IAP can protect SSH and RDP access to your VMs hosted on Google Cloud. Your VM instances don't even need public IP addresses. https://cloud.google.com/iap#section-2
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago