GCP Professional Cloud Security Engineer Practice Question
Your financial-services security team is creating a controls matrix for auditors before moving a payment-processing workload to Compute Engine. The document must list activities that remain solely the customer's responsibility under Google Cloud's shared responsibility model for IaaS services. Which activity will your organization, and not Google, be accountable for implementing and maintaining?
Monitoring and replacing failed physical storage devices in the data centers where your persistent disks reside.
Patching the hypervisor layer that hosts your virtual machines to address newly disclosed vulnerabilities.
Encrypting data stored on persistent disks at the storage layer using Google-supplied AES-256 encryption.
Regularly applying security patches to the guest operating system and configuring host-based firewalls on each Compute Engine VM.
With Infrastructure-as-a-Service offerings such as Compute Engine, Google secures the underlying physical infrastructure, storage devices, and virtualization stack, including hypervisor patching and disk replacement. Google also automatically encrypts data at rest on persistent disks with platform-managed keys, so the baseline encryption service is provided by Google. By contrast, everything inside the virtual machine-including the guest operating system configuration, operating system patch level, and host-based firewalls-remains entirely the customer's responsibility. Therefore, applying critical patches to the guest OS and configuring instance-level firewalls is an activity the customer must perform, whereas Google remains responsible for hypervisor patching, disk encryption at the physical layer, and physical data-center operations.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Google Cloud's shared responsibility model in IaaS services?
Open an interactive chat with Bash
Why is managing the guest OS the customer’s responsibility in Compute Engine?
Open an interactive chat with Bash
How does Google automatically encrypt data on persistent disks in Google Cloud?
Open an interactive chat with Bash
What is the shared responsibility model in Google Cloud for IaaS?
Open an interactive chat with Bash
What are guest operating system patches and why are they important?
Open an interactive chat with Bash
How does Google encrypt data at rest on persistent disks?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Supporting compliance requirements
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .