GCP PSE Certification Exam with all Correct & 100%
Verified Answers |Latest Version |Already Graded A+
227. You are migrating your users to Google Cloud. There are cookie replay attacks with Google
web and Google Cloud CLI SDK sessions on endpoint devices. You need to reduce the risk of
these threats.
What should you do? (Choose two.)
A. Configure Google session control to a shorter duration.
B. Set an organizational policy for OAuth 2.0 access token with a shorter duration.
C. Set a reauthentication policy for Google Cloud services to a shorter duration.
D. Configure a third-party identity provider with session management.
E. Enforce Security Key Authentication with 2SV. ✔Correct Answer-B. Set an organizational
policy for OAuth 2.0 access token with a shorter duration.
E. Enforce Security Key Authentication with 2SV.
219. You are migrating an on-premises data warehouse to BigQuery, Cloud SQL, and Cloud
Storage. You need to configure security services in the data warehouse. Your company
compliance policies mandate that the data warehouse must:• Protect data at rest with full
lifecycle management on cryptographic keys.• Implement a separate key management provider
from data management.• Provide visibility into all encryption key requests.What services should
be included in the data warehouse implementation? (Choose two.)
A. Customer-managed encryption keys
B. Customer-Supplied Encryption Keys
C. Key Access Justifications
D. Access Transparency and Approval
E. Cloud External Key Manager ✔Correct Answer-C. Key Access Justifications
E. Cloud External Key Manager
209. Your organization is transitioning to Google Cloud. You want to ensure that only trusted
container images are deployed on Google Kubernetes Engine (GKE) clusters in a project. The
containers must be deployed from a centrally managed Container Registry and signed by a
trusted authority.What should you do? (Choose two.)
A. Enable Container Threat Detection in the Security Command Center (SCC) for the project.
B. Configure the trusted image organization policy constraint for the project.
C. Create a custom organization policy constraint to enforce Binary Authorization for Google
Kubernetes Engine (GKE).
D. Enable PodSecurity standards, and set them to Restricted.
E. Configure the Binary Authorization policy with respective attestations for the project.
✔Correct Answer-B. Configure the trusted image organization policy constraint for the project.
E. Configure the Binary Authorization policy with respective attestations for the project.
Verified Answers |Latest Version |Already Graded A+
227. You are migrating your users to Google Cloud. There are cookie replay attacks with Google
web and Google Cloud CLI SDK sessions on endpoint devices. You need to reduce the risk of
these threats.
What should you do? (Choose two.)
A. Configure Google session control to a shorter duration.
B. Set an organizational policy for OAuth 2.0 access token with a shorter duration.
C. Set a reauthentication policy for Google Cloud services to a shorter duration.
D. Configure a third-party identity provider with session management.
E. Enforce Security Key Authentication with 2SV. ✔Correct Answer-B. Set an organizational
policy for OAuth 2.0 access token with a shorter duration.
E. Enforce Security Key Authentication with 2SV.
219. You are migrating an on-premises data warehouse to BigQuery, Cloud SQL, and Cloud
Storage. You need to configure security services in the data warehouse. Your company
compliance policies mandate that the data warehouse must:• Protect data at rest with full
lifecycle management on cryptographic keys.• Implement a separate key management provider
from data management.• Provide visibility into all encryption key requests.What services should
be included in the data warehouse implementation? (Choose two.)
A. Customer-managed encryption keys
B. Customer-Supplied Encryption Keys
C. Key Access Justifications
D. Access Transparency and Approval
E. Cloud External Key Manager ✔Correct Answer-C. Key Access Justifications
E. Cloud External Key Manager
209. Your organization is transitioning to Google Cloud. You want to ensure that only trusted
container images are deployed on Google Kubernetes Engine (GKE) clusters in a project. The
containers must be deployed from a centrally managed Container Registry and signed by a
trusted authority.What should you do? (Choose two.)
A. Enable Container Threat Detection in the Security Command Center (SCC) for the project.
B. Configure the trusted image organization policy constraint for the project.
C. Create a custom organization policy constraint to enforce Binary Authorization for Google
Kubernetes Engine (GKE).
D. Enable PodSecurity standards, and set them to Restricted.
E. Configure the Binary Authorization policy with respective attestations for the project.
✔Correct Answer-B. Configure the trusted image organization policy constraint for the project.
E. Configure the Binary Authorization policy with respective attestations for the project.