🔥 40% Off Crucial Exams Memberships — Deal ends today!

12 minutes, 0 second remaining!

GCP Professional Cloud Security Engineer Practice Question

Your company operates several regional managed instance groups (MIGs) that serve a latency-sensitive web application. Security policy requires every VM to be rebuilt from a CIS-hardened image that includes the latest operating-system security patches within 48 hours of release. Operations also needs an immutable, auditable history of all image versions and wants to roll out updates with near-zero user-visible downtime. What is the most effective way to meet these requirements?

  • Use OS patch management to run an in-place patch job that installs updates and reboots all VMs during a scheduled two-hour weekend maintenance window.

  • Provision a temporary bastion host after each patch release, connect via SSH to every VM to apply hardening scripts manually, and terminate the bastion afterward.

  • Configure a Cloud Build trigger that runs a Packer template nightly to create CIS-hardened, fully patched Compute Engine images, publish each build as a new version in a dedicated image family, update MIG instance templates to the latest family image, and launch rolling updates with maxSurge at 30 percent and maxUnavailable at 0.

  • Continue deploying public Debian images and add a startup script that executes apt-get update && apt-get upgrade on every boot to pull the latest security fixes.

GCP Professional Cloud Security Engineer
Managing operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot