GCP Professional Cloud Architect Practice Question
Your organization is preparing its first formal penetration test since migrating a public-facing payment application from an on-premises data center to Google Cloud. The workload now consists of a Cloud Load Balancer in front of Cloud Run services, which in turn access a Cloud SQL database. As the lead cloud architect, you must define the scope and approach of the exercise so that it reveals the most critical weaknesses while complying with Google Cloud policies and minimizing business risk. Which plan best meets these requirements?
Test both the Cloud Run application and the underlying Google Cloud environment by combining dynamic application attacks with reviews of IAM roles, service-account permissions, firewall rules, and Cloud SQL exposure. Use Security Command Center to augment manual testing, and proceed without additional Google approval as long as the tests comply with the Acceptable Use Policy.
Limit the engagement to external network vulnerability scans that probe for open ports on the Cloud Load Balancer, analyze Cloud NAT logs for anomalies, and submit a penetration-testing request to Google at least two weeks in advance for authorization.
Restrict testing to the application's HTTP endpoints only, excluding Google Cloud IAM and network settings, and run an open-source dynamic scanner from the on-premises network to avoid affecting production traffic.
Focus primarily on verifying that GKE node operating systems are fully patched and let Forseti Security perform automated scans; open a separate support case with Google for explicit approval of each individual test scenario before execution.
The most effective and compliant plan is to test both the application layer and the surrounding Google Cloud configuration. Modern cloud-focused penetration tests need to combine traditional web-application techniques (for example, injection and authentication bypass against the Cloud Run services) with attempts to exploit or mis-use cloud-native controls such as IAM roles, service accounts, network segmentation, and Cloud SQL exposure. Google no longer requires customers to obtain pre-approval for penetration testing of their own Google Cloud resources, provided that tests stay within the customer's projects and follow the Acceptable Use Policy. Relying only on external port scans, limiting scope to operating-system patch levels, or requesting unnecessary approvals would either miss key attack vectors or add needless overhead. Therefore, the comprehensive, policy-compliant approach that leverages Security Command Center findings plus targeted manual techniques is the correct choice.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Google Cloud's Acceptable Use Policy?
Open an interactive chat with Bash
What is Security Command Center in Google Cloud?
Open an interactive chat with Bash
What is the role of IAM in securing Google Cloud environments?
Open an interactive chat with Bash
What is Google Cloud's Acceptable Use Policy, and why is it important for penetration testing?
Open an interactive chat with Bash
How does Security Command Center assist in penetration testing for Google Cloud?
Open an interactive chat with Bash
What penetration testing techniques are commonly used for Cloud Run applications?
Open an interactive chat with Bash
GCP Professional Cloud Architect
Ensuring solution and operations excellence
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .