GCP Professional Cloud Security Engineer Practice Question

Your security team maintains a hardened Ubuntu image that Cloud Build rebuilds weekly and pushes to Artifact Registry with a timestamp tag. Hundreds of stateless front-end VMs run in several zonal managed instance groups (MIGs) that currently reference the previous image version. Compliance requires every VM to run the latest image within 24 hours of its publication, with zero downtime and no human intervention. Which solution best meets these requirements?

  • Point each managed instance group's instance template to the image's family and set the group's updatePolicy type to OPPORTUNISTIC so that instances automatically refresh when a new family image appears.

  • Create a Cloud Scheduler job that replaces each VM's boot disk with a snapshot of the new image during low-traffic hours.

  • Add steps to the Cloud Build pipeline that, after the new image is pushed, create an updated instance template and invoke a managed instance group rolling update with maxSurge set to 25 % and maxUnavailable set to 0.

  • Configure OS Config patch jobs to run weekly and apply all available security patches in place, forcing a reboot of each VM after patching.

GCP Professional Cloud Security Engineer
Managing operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot