GCP Professional Cloud Architect Practice Question

Your security team plans a quarterly penetration test against a production environment that runs workloads on a GKE Autopilot cluster and stores data in Cloud SQL. Planned activities include: (1) automated vulnerability scans against the cluster's workloads and the Cloud SQL public endpoint, and (2) attempts to exploit the underlying hypervisor of the Cloud SQL instance. According to Google Cloud's shared responsibility model and penetration-testing policy, how should the team proceed?

  • Proceed with both activities without notifying Google, because customers can test any resource located in their own projects.

  • Request formal pre-approval from Google but otherwise run all planned tests, because penetration testing always requires Google's authorization.

  • Proceed with the vulnerability scans against the GKE workloads and Cloud SQL endpoint without prior approval, but omit any attempt to target the hypervisor since that is Google-managed infrastructure.

  • Cancel all testing and rely on Google's internal penetration tests, because security of workloads hosted on managed services is Google's responsibility under the shared responsibility model.

GCP Professional Cloud Architect
Analyzing and optimizing technical and business processes
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot