exam questions

Exam Professional Cloud Security Engineer All Questions

View all questions & answers for the Professional Cloud Security Engineer exam

Exam Professional Cloud Security Engineer topic 1 question 11 discussion

Actual exam question from Google's Professional Cloud Security Engineer
Question #: 11
Topic #: 1
[All Professional Cloud Security Engineer Questions]

A customer needs to prevent attackers from hijacking their domain/IP and redirecting users to a malicious site through a man-in-the-middle attack.
Which solution should this customer use?

  • A. VPC Flow Logs
  • B. Cloud Armor
  • C. DNS Security Extensions
  • D. Cloud Identity-Aware Proxy
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ESP_SAP
Highly Voted 2 years, 5 months ago
Correct Answer is (C): DNSSEC — use a DNS registrar that supports DNSSEC, and enable it. DNSSEC digitally signs DNS communication, making it more difficult (but not impossible) for hackers to intercept and spoof. Domain Name System Security Extensions (DNSSEC) adds security to the Domain Name System (DNS) protocol by enabling DNS responses to be validated. Having a trustworthy Domain Name System (DNS) that translates a domain name like www.example.com into its associated IP address is an increasingly important building block of today’s web-based applications. Attackers can hijack this process of domain/IP lookup and redirect users to a malicious site through DNS hijacking and man-in-the-middle attacks. DNSSEC helps mitigate the risk of such attacks by cryptographically signing DNS records. As a result, it prevents attackers from issuing fake DNS responses that may misdirect browsers to nefarious websites. https://cloud.google.com/blog/products/gcp/dnssec-now-available-in-cloud-dns
upvoted 15 times
...
Kameswara
Highly Voted 1 year, 11 months ago
C. Attackers can hijack this process of domain/IP lookup and redirect users to a malicious site through DNS hijacking and man-in-the-middle attacks. DNSSEC helps mitigate the risk of such attacks by cryptographically signing DNS records. As a result, it prevents attackers from issuing fake DNS responses that may misdirect browsers to nefarious websites.
upvoted 5 times
...
AzureDP900
Most Recent 5 months, 3 weeks ago
C is right
upvoted 2 times
...
GCP72
8 months ago
Selected Answer: C
The correct answer is C
upvoted 3 times
...
minostrozaml2
1 year, 3 months ago
Took the tesk today, only 5 question from this dump, the rest are new questions.
upvoted 2 times
...
shreenine
1 year, 6 months ago
C is the correct answer indeed.
upvoted 3 times
...
sc_cloud_learn
1 year, 11 months ago
C. DNSSEC is the ans
upvoted 2 times
...
ASG
2 years, 2 months ago
Its man in the middle attack protection. The traffic first needs to reach cloud armour before you can make use of cloud armour related protection. DNS can be hijacked if you dont use DNSSEC. Its your DNS that needs to resolve the initial request before traffic is directed to cloud armour. Option C is most appropriate measure. (think of sequencing of how traffic will flow)
upvoted 3 times
...
bolu
2 years, 3 months ago
The answers from rest of the folks are complete unreliable. The right answer is Cloud Armor based on my Hands-On labs in Qwiklabs. Reason: Creating a policy in Cloud Armor sends 403 forbidden message for man-in-the middle-attack. Reference: https://cloud.google.com/blog/products/identity-security/identifying-and-protecting-against-the-largest-ddos-attacks Some more: https://cloud.google.com/armor Refer this lab: https://www.qwiklabs.com/focuses/1232?catalog_rank=%7B%22rank%22%3A1%2C%22num_filters%22%3A0%2C%22has_search%22%3Atrue%7D&parent=catalog&search_id=8696512
upvoted 2 times
KyubiBlaze
1 year, 7 months ago
No, C is the correct answer.
upvoted 1 times
...
...
[Removed]
2 years, 6 months ago
Ans - C
upvoted 2 times
...
saurabh1805
2 years, 6 months ago
DNSEC is the thing, Option C
upvoted 2 times
...
MohitA
2 years, 8 months ago
C, Yes for sure DNSSEC
upvoted 2 times
...
bigdo
2 years, 8 months ago
C DNSSEC
upvoted 2 times
...
ArizonaClassics
2 years, 8 months ago
Option C is Perfect. DNSSECURITY!
upvoted 2 times
...
KILLMAD
3 years, 1 month ago
I agree it's C
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago