GCP Professional Cloud Security Engineer Practice Question
A financial-services company is creating a responsibility matrix for three Google Cloud workloads: (1) a batch engine on Compute Engine VMs, (2) a web app on App Engine standard environment, and (3) corporate email in Google Workspace. Which security control will the company manage only for the Compute Engine workload, will become Google's responsibility on App Engine, and is already fully handled by Google for Google Workspace?
Turning on and reviewing Access Transparency logs for provider support actions.
Ensuring that Google-managed encryption keys are enabled for data at rest.
Maintaining the physical security and environmental controls of the data centers.
Hardening and regularly patching the guest operating system.
Under Google Cloud's shared responsibility model, guest operating-system hardening and patching is the customer's duty for IaaS offerings such as Compute Engine because the customer controls the VM image and operating system layer. In the App Engine standard environment, Google manages the underlying OS and runtime, so responsibility for OS patching shifts to Google. For SaaS offerings like Google Workspace, Google already manages the entire application stack, including the operating system.
Encrypting data at rest with Google-managed keys and protecting data-center facilities are always Google's responsibilities across IaaS, PaaS, and SaaS, so they do not meet the "Compute Engine only" criterion. Access Transparency must be enabled and monitored by the customer for any eligible service, so that task remains with the customer across all three workloads.
Therefore, guest operating-system hardening and patching is the only control uniquely managed by the customer on Compute Engine but not on App Engine or Google Workspace.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the shared responsibility model in Google Cloud?
Open an interactive chat with Bash
Why is guest operating-system hardening and patching the customer's responsibility for Compute Engine?
Open an interactive chat with Bash
How does Google handle security for App Engine and Google Workspace?
Open an interactive chat with Bash
What is the shared responsibility model in Google Cloud Platform?
Open an interactive chat with Bash
Why is guest OS hardening necessary for security?
Open an interactive chat with Bash
What is Access Transparency, and why is it important?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Supporting compliance requirements
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .