GCP Professional Cloud Security Engineer Practice Question

Your organization operates three GKE clusters in separate projects, all attached to the same VPC network. Only workloads in the production subnet 10.20.0.0/16 located in europe-west1 must be inspected for command-and-control traffic, and the security team wants to query detections with SQL in near real time. You have been asked to design this solution while avoiding any self-managed network-inspection appliances. Which approach should you recommend?

  • Deploy a fleet of third-party intrusion-detection virtual appliances in a shared VPC service project, mirror all VPC traffic to them, and export VPC Flow Logs to BigQuery for later analysis.

  • Install an open-source IDS DaemonSet on each GKE cluster for inline inspection and use Pub/Sub with Cloud Functions to batch-export the resulting logs to Cloud Storage for monthly review.

  • Create a single Cloud IDS endpoint in us-central1, peer each project's VPC to a dedicated security VPC in that region, mirror all VPC traffic to the IDS endpoint, and export only Cloud Audit Logs to BigQuery.

  • In each project, deploy a Cloud IDS endpoint in europe-west1, configure a Packet Mirroring policy that selects traffic with source subnet 10.20.0.0/16, and create a centralized Log Router sink that streams "networksecurity.googleapis.com/firewall_threat" logs from Cloud Logging to a BigQuery dataset for analysis.

GCP Professional Cloud Security Engineer
Managing operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot