GCP Professional Cloud Security Engineer Practice Question

Your banking platform is expanding to four Google Cloud projects, each hosting GKE clusters that communicate over a service mesh. Compliance mandates mutual TLS for all service-to-service traffic with certificates issued from an internal private PKI whose root must remain offline. Certificates must have a 24-hour lifetime and be rotated automatically. Operations insists on a managed service that offers an SLA for certificate issuance and supports API-driven automation as well as seamless CA key rotation. Which approach best meets these requirements?

  • Use Google Cloud Public Certificate Authority to issue publicly trusted certificates and push them to workloads using Workload Identity.

  • Configure Google-managed SSL certificates on an external HTTP(S) load balancer and distribute the certificates to the clusters via Secret Manager for mutual TLS.

  • Provision a Certificate Authority Service Enterprise-tier CA pool with an offline root CA and subordinate issuing CAs, and automate 24-hour certificate issuance for the service mesh through CAS APIs.

  • Operate a self-hosted OpenSSL root CA on a Compute Engine VM, sign service CSRs in the CI/CD pipeline, and rotate keys manually on an annual schedule.

GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot