🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 53 minutes remaining!

GCP Professional Cloud Security Engineer Practice Question

Your security team maintains a Git repository containing CIS benchmark hardening scripts for Debian-based workloads. They require that every new Compute Engine VM and every GKE node pool boot from an image that was built with those scripts. Other projects across the organization must be able to consume, but not modify, the images, and the newest patch level should be selected automatically at instance creation time. With minimal operational overhead, which architecture best satisfies these requirements?

  • Maintain Deployment Manager templates that embed the hardening scripts as startup scripts; give each consumer project deploymentmanager.editor to deploy the templates when creating resources.

  • Build hardened container images with Cloud Build, store them in Artifact Registry, and use Container-Optimized OS nodes so that GKE pulls the images for node pools.

  • Schedule weekly OS Config patch jobs in every project; at boot time VMs download the CIS scripts from Cloud Storage and run them through startup scripts.

  • Trigger Cloud Build on repository changes to run a Packer template that applies the hardening scripts, creates a custom image in a dedicated "golden-images" project, assigns the image to an image family, and grants consumer projects the compute.imageUser role on that project.

GCP Professional Cloud Security Engineer
Managing operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot