GCP Professional Cloud Security Engineer Practice Question

Your company hosts the public DNS zone corp.example in Cloud DNS. After investigating recent cache-poisoning attempts, the security team asks you to implement a control that allows validating recursive resolvers on the internet to cryptographically verify that the answers they receive for corp.example are authentic and untampered. The operations team wants a solution that minimizes ongoing key-management overhead for them. What should you do?

  • Enable DNSSEC for the Cloud DNS managed zone, rely on Cloud DNS to create and automatically rotate the ZSK, manually manage the KSK, and publish the generated DS record with the domain registrar.

  • Enforce DNS over TLS for all clients and block UDP/53 on the corporate firewall to prevent on-path tampering of DNS responses.

  • Deploy secondary authoritative DNS servers in another project and front them with Cloud CDN so cached DNS responses remain available during outages.

  • Enable Cloud DNS query logging and create Cloud Logging alerts to detect suspicious NXDOMAIN or SERVFAIL spikes indicating cache-poisoning attempts.

GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot