Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam Professional Cloud Security Engineer All Questions

View all questions & answers for the Professional Cloud Security Engineer exam

Exam Professional Cloud Security Engineer topic 1 question 44 discussion

Actual exam question from Google's Professional Cloud Security Engineer
Question #: 44
Topic #: 1
[All Professional Cloud Security Engineer Questions]

Your company is using GSuite and has developed an application meant for internal usage on Google App Engine. You need to make sure that an external user cannot gain access to the application even when an employee's password has been compromised.
What should you do?

  • A. Enforce 2-factor authentication in GSuite for all users.
  • B. Configure Cloud Identity-Aware Proxy for the App Engine Application.
  • C. Provision user passwords using GSuite Password Sync.
  • D. Configure Cloud VPN between your private network and GCP.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
rafaelc
Highly Voted 4 years, 8 months ago
A. Enforce 2-factor authentication in GSuite for all users.
upvoted 21 times
...
johnsm
Highly Voted 3 years, 3 months ago
Correct answer is A. Well explained here: https://docs.google.com/document/d/11o3e14tyhnT7w45Q8-r9ZmTAfj2WUNUpJPZImrxm_F4/edit?usp=sharing found some other answers for other questions in this site as well.
upvoted 8 times
...
coompiler
Most Recent 1 month ago
Selected Answer: B
I go with B. IAP is zero trust and context aware
upvoted 1 times
...
coompiler
1 month ago
I go with B. IAP is zero trust and context aware
upvoted 1 times
...
PankajKapse
2 months ago
Selected Answer: B
I also feel, it's B. As even if password is compromised, we can block based on IP ranges, geolocation, etc
upvoted 1 times
...
Oujay
4 months, 3 weeks ago
Selected Answer: B
A Cloud VPN creates a secure tunnel between your network and GCP, but it wouldn't restrict access based on individual user identities.
upvoted 2 times
...
Oujay
4 months, 3 weeks ago
2FA adds an extra layer of security, but if an external user has both the password and the second factor (e.g., a verification code), they might still gain access. So my answer is B. All external users will be blocked with the right authentication or not
upvoted 1 times
...
dbf0a72
10 months, 3 weeks ago
Selected Answer: A
A is the answer.
upvoted 1 times
...
raj117
1 year, 4 months ago
Right Answer is A
upvoted 2 times
...
SMB2022
1 year, 4 months ago
Correct Answer A
upvoted 2 times
...
AwesomeGCP
2 years, 1 month ago
Selected Answer: A
A is the answer.
upvoted 3 times
...
sudarchary
2 years, 9 months ago
Selected Answer: A
https://support.google.com/a/answer/175197?hl=en
upvoted 2 times
...
Jane111
3 years, 7 months ago
Shouldn't it be B. Configure Cloud Identity-Aware Proxy for the App Engine Application. identity based app access
upvoted 4 times
[Removed]
1 year, 4 months ago
I was thinking the same thing. Turns out IAP ensures security by enforcing 2FA. So at the end of the day, 2FA is the real solution. 2FA without IAP would still address the risk. IAP without 2FA might not. https://cloud.google.com/iap/docs/configuring-reauth#supported_reauthentication_methods
upvoted 2 times
...
...
desertlotus1211
3 years, 8 months ago
The key is external user. Best practice is to have internal users/datacenter connect via VPN for security purpose, correct? External users will try to connect via Internet - they still cannot reach the app engine even if they have a users' password because a VPN connection is need to reach the resource. MA will work IF the external user has VPN access... But I think D is what they're looking for based on the question....
upvoted 3 times
mynk29
2 years, 9 months ago
Agree but there is no mention that external user doesnt have internal network access too. A is better option as it covers both scenarios.
upvoted 2 times
...
...
DebasishLowes
3 years, 8 months ago
Ans : A. When passwords is compromised, enforcing 2 factor authentication is the best way to prevent non authorized users.
upvoted 2 times
...
soukumar369
3 years, 11 months ago
Enforcing 2-factor authentication can save an employee's password has been compromised
upvoted 2 times
...
soukumar369
3 years, 11 months ago
Enforce 2-factor authentication safe employee, when an employee's password has been compromised.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...