GCP Professional Cloud Security Engineer Practice Question

Your company is launching a multi-region e-commerce platform on Google Cloud. A global external Application Load Balancer has already been deployed to distribute traffic to GKE back-ends. Security policy requires that traffic is encrypted with a certificate that is automatically provisioned and rotated by Google and that a single certificate secures both shop.example.com and api.example.com. Which approach meets these requirements with the least operational effort?

  • Create a Google-managed certificate resource in Certificate Manager that lists both hostnames, update public A and AAAA records to resolve the names to the load balancer's global forwarding rule IP, and attach the certificate to the load balancer's target HTTPS proxy.

  • Annotate the GKE Ingress with the ssl-cert annotation and create two separate managed certificates, one per hostname; rely on the Kubernetes Ingress controller to terminate TLS on the GKE nodes.

  • Enable Cloud Armor Advanced on the load balancer and select automatic SSL; Google will issue and rotate certificates without further configuration.

  • Generate a CSR on a bastion host, purchase a public certificate for each hostname, import the certificates and private keys into Cloud Key Management Service, and reference them from the backend services.

GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot