exam questions

Exam Professional Cloud Security Engineer All Questions

View all questions & answers for the Professional Cloud Security Engineer exam

Exam Professional Cloud Security Engineer topic 1 question 16 discussion

Actual exam question from Google's Professional Cloud Security Engineer
Question #: 16
Topic #: 1
[All Professional Cloud Security Engineer Questions]

An organization's typical network and security review consists of analyzing application transit routes, request handling, and firewall rules. They want to enable their developer teams to deploy new applications without the overhead of this full review.
How should you advise this organization?

  • A. Use Forseti with Firewall filters to catch any unwanted configurations in production.
  • B. Mandate use of infrastructure as code and provide static analysis in the CI/CD pipelines to enforce policies.
  • C. Route all VPC traffic through customer-managed routers to detect malicious patterns in production.
  • D. All production applications will run on-premises. Allow developers free rein in GCP as their dev and QA platforms.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
bluetaurianbull
Highly Voted 3 years ago
@TNT87 and others, if you say (B) or even (C) or (A) can you provide proof and URLs to support your claims. Simply saying if you have done Cloud Architect you will know Everything under the sun is not the proper response, this is a discussion and a community here trying to learn. Not everyone will be in same standard or level. Be helpful for others please....
upvoted 16 times
[Removed]
9 months, 1 week ago
Here you go for "B" https://www.terraform.io/use-cases/enforce-policy-as-code
upvoted 1 times
...
...
OSNG
Highly Voted 2 years, 7 months ago
Its B. Reasons: 1. They are asking for advise for Developers. (IaC is the suitable as they don't have to worry about managing infrastructure manually). Moreover "An organization’s typical network and security review consists of analyzing application transit routes, request handling, and firewall rules." statement is defining the process, they are not asking about the option to review the rules. Using Forseti is not reducing the overhead for Developers.
upvoted 10 times
...
ppandher
Most Recent 6 months, 1 week ago
They want to enable their developer teams to deploy new applications without the overhead of this full review - Questions says this . I am not sure if that feature is available in Forseti as per it, it is Inventory, Scanner, Explain, Enforce & Notification .
upvoted 1 times
...
[Removed]
9 months, 1 week ago
Selected Answer: B
The question emphasizes infrastructure related overhead. "B" is there only answer that addresses infrastructure overhead by leveraging infrastructure as code. Specifically the overhead is around security and policy concerns which are addressed by terraform in what they call "policy as code". https://www.terraform.io/use-cases/enforce-policy-as-code
upvoted 1 times
...
TonytheTiger
1 year, 5 months ago
B: the best answer. https://cloud.google.com/recommender/docs/tutorial-iac
upvoted 1 times
...
GCP72
1 year, 8 months ago
Selected Answer: B
The correct answer is B
upvoted 1 times
...
Jeanphi72
1 year, 8 months ago
Selected Answer: A
The problem I see with B is that there is no reason why reviews should disappear: IaC is code and code needs to be reviewed before being deployed. Depending on the companies, devops writing terraform / CDK are named developers as well. Forseti seems to be able to automate this: https://github.com/forseti-security/forseti-security/tree/master/samples/scanner/scanners
upvoted 1 times
...
szl0144
1 year, 11 months ago
I think B is the answer, can anybody explain why A is correct?
upvoted 1 times
badrik
1 year, 10 months ago
A is detective in nature while B is preventive. So, It's B !
upvoted 2 times
...
...
minostrozaml2
2 years, 3 months ago
Took the tesk today, only 5 question from this dump, the rest are new questions.
upvoted 2 times
...
ThisisJohn
2 years, 4 months ago
Selected Answer: B
My vote goes to B by discard. A) only mentions firewall rules, but nothing about network routes, and nothing on Forseti website either https://forsetisecurity.org/about/ C) Talks about malicious patterns, not about network routes, requests handling and patterns, like the question says D) Running on-prem doesn't guarantee a higher level of control Thus, the only answer that makes sense for me is B
upvoted 2 times
...
TNT87
3 years, 2 months ago
if you done Cloud Rchitect,you will understand why the answer is B
upvoted 4 times
bluetaurianbull
2 years, 11 months ago
its like saying if you have gone to space you experiance weighlessness .. be professional man... give proof for your claims, dont just expect world to be in same level as you. thats about COMMUNITY LEARNING ...
upvoted 10 times
TNT87
1 year, 1 month ago
kkkkkkkkkkkkk then research than being angry
upvoted 1 times
...
...
...
[Removed]
3 years, 6 months ago
Ans - C
upvoted 2 times
[Removed]
3 years, 6 months ago
Sry(Typo) .. It's B
upvoted 2 times
...
...
saurabh1805
3 years, 6 months ago
I will also go with option A
upvoted 1 times
...
CHECK666
3 years, 7 months ago
B is the answer
upvoted 1 times
...
ownez
3 years, 8 months ago
Answer is B and not A because in A, the answer provided tells us the environment is in production where the question is about to enable their developer teams to deploy new applications without the overhead of the full review. Implementation of IAC is suitable for this. Answer is B.
upvoted 3 times
...
MohitA
3 years, 8 months ago
Yes B serves the purpose.
upvoted 2 times
...
aiwaai
3 years, 8 months ago
Answer is A
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago