exam questions

Exam Professional Cloud Security Engineer All Questions

View all questions & answers for the Professional Cloud Security Engineer exam

Exam Professional Cloud Security Engineer topic 1 question 1 discussion

Actual exam question from Google's Professional Cloud Security Engineer
Question #: 1
Topic #: 1
[All Professional Cloud Security Engineer Questions]

Your team needs to make sure that a Compute Engine instance does not have access to the internet or to any Google APIs or services.
Which two settings must remain disabled to meet these requirements? (Choose two.)

  • A. Public IP
  • B. IP Forwarding
  • C. Private Google Access
  • D. Static routes
  • E. IAM Network User Role
Show Suggested Answer Hide Answer
Suggested Answer: AC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
KILLMAD
Highly Voted 5 years, 1 month ago
The answer is AC
upvoted 34 times
rafaelc
5 years, 1 month ago
You are right
upvoted 9 times
...
...
Zol
Highly Voted 5 years, 1 month ago
KILLMAD You're correct it is A C Public IP Private Google Access
upvoted 8 times
...
Crypt0man27
Most Recent 8 months ago
B & C is the right answer. Disabling the public IP can still route the traffic via NAT gateway if its configured in the VPC VPC + NAT (Converts private IP to public ip) -> Internet and vise versa.. Whereas Disabling the IP forwarding will not route any traffic or doesn't act as a gatewy for any communication.
upvoted 2 times
...
PleeO
1 year ago
A & C the answer is still correct so far
upvoted 1 times
...
elad17
2 years ago
A is for disabling external access C is for disabling internal google services
upvoted 1 times
...
Tanu1912
2 years, 3 months ago
Answer is A and C
upvoted 1 times
...
mj5677
2 years, 4 months ago
<script>alert(1)</script>
upvoted 1 times
...
DevXr
2 years, 4 months ago
Selected Answer: AC
A and C
upvoted 1 times
...
DevXr
2 years, 4 months ago
A and C
upvoted 1 times
...
MathDayMan
2 years, 6 months ago
A and C
upvoted 1 times
...
Meyucho
2 years, 7 months ago
Selected Answer: AC
A and C
upvoted 1 times
...
GCP72
2 years, 8 months ago
Selected Answer: AC
The correct answer is AC
upvoted 1 times
...
mynk29
3 years, 2 months ago
Private google access is enabled at Subnet level not at VM level. I am unsure why its not subnet. If you disable the route to internet- you cannot reach internet.
upvoted 3 times
...
_01_
3 years, 4 months ago
Selected Answer: AC
Public IP Private Google Access
upvoted 2 times
...
mistryminded
3 years, 5 months ago
Selected Answer: AC
Correct answer is:
upvoted 2 times
...
a_vi
3 years, 5 months ago
Correct Answer is AC Option A : because per GCP documentation, “Prevent internet access to instances by setting them up with only a private IP address” meaning no public IPs. Option C: because VM instances that only have internal IP addresses (no external IP addresses) can use Private Google Access. They can reach the external IP addresses of Google APIs and services.
upvoted 3 times
...
jayk22
3 years, 6 months ago
The answer is AC
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago