GCP Professional Cloud Security Engineer Practice Question

Your financial services company uses three Google Cloud offerings: Compute Engine VMs for core banking applications, GKE Autopilot clusters for customer-facing APIs, and BigQuery for data analytics. The CISO is drafting a policy that assigns your team responsibility for applying operating-system security patches across all in-scope services. According to Google Cloud's shared responsibility model, how should you advise the CISO?

  • Discard the policy, since Google is responsible for operating-system security across all Google Cloud services, including Compute Engine VMs.

  • Update the policy to require OS patching on both Compute Engine and GKE Autopilot, but not on BigQuery, because Google manages operating systems only for SaaS services.

  • Keep the policy as written because customers must patch the operating system on every Google Cloud service they use.

  • Update the policy to state that the team patches guest operating systems only on Compute Engine; Google manages OS patching for GKE Autopilot nodes and for the BigQuery service.

GCP Professional Cloud Security Engineer
Supporting compliance requirements
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot