GCP Professional Cloud Security Engineer Practice Question

Your security team is deploying Google Cloud Secure Web Proxy (SWP) to inspect outbound HTTPS traffic from VM-based workloads in multiple VPC networks. The goal is to perform full TLS inspection without introducing unmanaged private keys while keeping certificate issuance scalable and centrally governed. Which approach best meets these requirements?

  • Configure SWP to use Cloud Load Balancing's Google-managed SSL certificates that are automatically provisioned and renewed.

  • Purchase publicly trusted TLS certificates from a commercial CA, upload the private keys to SWP, and enable automatic certificate rotation.

  • Create an internal subordinate CA in Certificate Authority Service backed by Google-managed HSM, add it to a dedicated CA pool, and configure Secure Web Proxy to request short-lived inspection certificates from that pool.

  • Generate a self-signed root certificate on each SWP proxy instance and distribute the public key to clients using a custom OS image.

GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot