GCP Professional Cloud Architect Practice Question

Your organization is preparing its first formal penetration test since migrating a public-facing payment application from an on-premises data center to Google Cloud. The workload now consists of a Cloud Load Balancer in front of Cloud Run services, which in turn access a Cloud SQL database. As the lead cloud architect, you must define the scope and approach of the exercise so that it reveals the most critical weaknesses while complying with Google Cloud policies and minimizing business risk. Which plan best meets these requirements?

  • Test both the Cloud Run application and the underlying Google Cloud environment by combining dynamic application attacks with reviews of IAM roles, service-account permissions, firewall rules, and Cloud SQL exposure. Use Security Command Center to augment manual testing, and proceed without additional Google approval as long as the tests comply with the Acceptable Use Policy.

  • Limit the engagement to external network vulnerability scans that probe for open ports on the Cloud Load Balancer, analyze Cloud NAT logs for anomalies, and submit a penetration-testing request to Google at least two weeks in advance for authorization.

  • Restrict testing to the application's HTTP endpoints only, excluding Google Cloud IAM and network settings, and run an open-source dynamic scanner from the on-premises network to avoid affecting production traffic.

  • Focus primarily on verifying that GKE node operating systems are fully patched and let Forseti Security perform automated scans; open a separate support case with Google for explicit approval of each individual test scenario before execution.

GCP Professional Cloud Architect
Ensuring solution and operations excellence
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot