Free Google Cloud Certified - Professional Cloud Security Engineer practice — 6 questions on Managing Operations, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Managing Operations
A platform team enabled Binary Authorization on a GKE cluster with a policy that requires an attestation from an attestor named 'vuln-scan-attestor' before any image can be deployed. The vulnerability scan step in Cloud Build passes, but the deployment step still fails because no valid attestation exists. Which action is required to allow the pipeline to produce a valid attestation that Binary Authorization will accept?
Producing a valid attestation requires a Container Analysis Note tied to the Attestor, plus signing the image digest with the KMS key referenced by that attestor's public key. Without this, Binary Authorization has nothing to verify.
Question 2 of 6 · Managing Operations
A security team wants a single organization-level log sink that exports Cloud Audit Logs (Admin Activity and Data Access) from every project in the organization into a BigQuery dataset in a centralized security project, except logs originating from the 'sandbox-testing' folder, which should never be exported. Which configuration meets this requirement with the least administrative overhead?
An organization-level aggregated sink with includeChildren=true automatically captures logs from all current and future projects/folders, and an exclusion filter is the supported mechanism to omit a specific folder's logs from that export, minimizing ongoing management.
Question 3 of 6 · Managing Operations
Security engineers must detect known malware command-and-control signatures and other network-based threats within east-west traffic between Compute Engine VMs in a single VPC, without inserting an inline device that could add latency or become a single point of failure. Which Google Cloud service should they deploy?
Cloud IDS is purpose-built for signature-based intrusion and malware detection. It relies on Packet Mirroring to analyze a copy of traffic out-of-band, so it adds no inline latency and is not a single point of failure.
Question 4 of 6 · Managing Operations
An organization needs automated detection for two distinct requirements: (1) flag any Compute Engine instance whose resource configuration does not include a mandatory 'data-classification' label, and (2) flag log-based evidence of anomalous IAM permission grants performed via unusual API call sequences. Which pairing correctly matches each requirement to the Security Command Center capability designed for it?
Security Health Analytics custom modules evaluate resource configuration (via Cloud Asset Inventory) using CEL expressions, which fits checking a missing label. Event Threat Detection custom modules analyze log streams using YARA-L rules, which fits detecting anomalous behavioral patterns in Cloud Audit Logs.
Question 5 of 6 · Managing Operations
A compliance mandate requires an immutable audit trail capturing every successful 'AccessSecretVersion' call made against secrets in Secret Manager, including calls made by project owners. The team left audit logging at its default configuration. A review shows no log entries exist for successful secret access calls. What must be changed?
Secret Manager fully supports Cloud Audit Logs, but Data Access logs (ADMIN_READ, DATA_READ, DATA_WRITE) are disabled by default for nearly all services, with BigQuery as the notable exception. They must be explicitly enabled via an Audit Config at the project or organization level to capture successful secret read access, including access by admins/owners.
Question 6 of 6 · Managing Operations
A security team must ensure that all Compute Engine VM instances across an organization automatically receive critical OS security patches within 48 hours of release, and must be able to generate compliance reports showing patch status per instance. Which Google Cloud capability should they configure?
VM Manager's OS Patch Management lets administrators define patch deployment schedules (including urgency-based windows suitable for a 48-hour SLA) and provides Patch Compliance dashboards/reports showing per-instance patch state, directly satisfying both automated patching and reporting requirements.
Ready for the real thing?
The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.