GCP Professional Cloud Security Engineer Practice Question
Your organization operates a managed instance group that runs a patient-data analytics workload on Compute Engine. The CISO is concerned that privileged cloud operators or a compromised hypervisor could read the virtual machines' memory during processing. Refactoring the application is not possible, and the instances must keep autoscaling across multiple zones. Which change will best protect the data while it is in use with minimal disruption to the existing deployment?
Enable Shielded VM with Secure Boot on the current instances.
Rewrite the workload to execute inside Cloud HSM and invoke it through an API from lightweight Compute Engine instances.
Encrypt the boot and data disks with customer-managed encryption keys (CMEK) and disable the serial console.
Update the instance template to use Confidential VMs and select a compatible confidential CPU platform.
Updating the instance template to use Confidential VMs enables hardware-based memory encryption with AMD SEV or Intel TDX, shielding data in use from the host hypervisor and Google operators without requiring application changes. Shielded VM provides boot-time integrity but leaves runtime memory unencrypted. Encrypting disks with CMEK secures data only at rest. Cloud HSM protects cryptographic keys and cannot run general analytics workloads.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are Confidential VMs in GCP?
Open an interactive chat with Bash
What is AMD SEV and how does it protect data in memory?
Open an interactive chat with Bash
How do Shielded VMs differ from Confidential VMs?
Open an interactive chat with Bash
What are Confidential VMs?
Open an interactive chat with Bash
How does AMD SEV or Intel TDX work in Confidential VMs?
Open an interactive chat with Bash
What is the difference between Shielded VM and Confidential VM?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Ensuring data protection
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .