GCP Professional Cloud Security Engineer Practice Question
Your data science team must train a deep-learning model on highly sensitive genomic data. For compliance reasons, they elect to build a custom training workflow on GPU-equipped Compute Engine instances instead of using Vertex AI's managed training service. Which control remains entirely the customer's responsibility in this IaaS approach but would have been handled by Google if Vertex AI were used?
Configuring Customer-Managed Encryption Keys (CMEK) for the Cloud Storage buckets that hold training data
Applying security patches and hardening the guest operating system on the training VMs
Creating a VPC Service Controls perimeter around the AI service endpoints to prevent data exfiltration
Granting least-privilege IAM roles to data scientists for access to the training pipeline
When you use custom training on Compute Engine, the VM guest operating system is under your administrative domain: you choose the image, apply security patches, and harden the OS. With Vertex AI's managed (PaaS) training, Google provisions and maintains the underlying hosts, including applying OS updates and security patches, so the customer is not responsible for that layer. Network policies, CMEK for data, and service-level IAM are still customer tasks in both models.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is IaaS and how does it differ from PaaS?
Open an interactive chat with Bash
What is OS hardening and why is it important for Compute Engine VMs?
Open an interactive chat with Bash
Why doesn’t using CMEK or IAM roles address the need for OS hardening?
Open an interactive chat with Bash
What is the difference between IaaS and PaaS in cloud computing?
Open an interactive chat with Bash
What does it mean to harden a guest operating system?
Open an interactive chat with Bash
What are Customer-Managed Encryption Keys (CMEK) and when should they be used?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Ensuring data protection
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .