Cloud Engineer Security & Identity Management Flashcards
6 cards from real Cloud Engineer practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Cloud Engineer Security & Identity Management flashcards as text
Which Cloud KMS key type gives you full control over key material and lets you import your own keys?
Answer: Customer-supplied encryption keys (CSEK)
Customer-supplied encryption keys (CSEK) allow you to provide your own key material to Google Cloud, giving you the highest level of key control.
What is the purpose of a Google Cloud Organization Policy?
Answer: Enforce guardrails on resource configuration across the organization
Organization Policies let administrators set constraints on GCP resource configurations (e.g., restricting allowed regions or disabling public IPs) across an entire organization.
Which Google Cloud service provides a managed certificate authority for issuing private SSL/TLS certificates?
Answer: Certificate Authority Service (CAS)
Certificate Authority Service (CAS) is a managed service that lets you create and manage private CAs for issuing internal TLS certificates.
A developer accidentally committed a service account key to a public GitHub repository. What is the FIRST action you should take?
Answer: Rotate the service account key immediately
Rotating (or deleting) the exposed key immediately prevents unauthorized use, as the key may already be compromised the moment it was publicly accessible.
What Google Cloud tool continuously scans GCP configurations for security misconfigurations and compliance violations?
Answer: Security Command Center
Security Command Center (SCC) is Google Cloud's centralized security management system that detects misconfigurations, vulnerabilities, and threats across GCP resources.
Which log type in Cloud Audit Logs records when an administrator changes IAM policies?
Answer: Admin Activity audit logs
Admin Activity audit logs capture all API calls that modify resource configurations or metadata, including IAM policy changes, and are always enabled.