Your team needs to make sure that a Compute Engine instance does not have access to the internet or to any Google APIs or services.
Which two settings must remain disabled to meet these requirements? (Choose two.)
Correct Answer:
AC
🗳️
Reference:
https://cloud.google.com/vpc/docs/configure-private-google-access
Which two implied firewall rules are defined on a VPC network? (Choose two.)
Correct Answer:
AB
🗳️
Reference:
https://cloud.google.com/vpc/docs/firewalls
A customer needs an alternative to storing their plain text secrets in their source-code management (SCM) system.
How should the customer achieve this using Google Cloud Platform?
Correct Answer:
B
🗳️
Your team wants to centrally manage GCP IAM permissions from their on-premises Active Directory Service. Your team wants to manage permissions by AD group membership.
What should your team do to meet these requirements?
Correct Answer:
B
🗳️
Reference:
https://cloud.google.com/blog/products/identity-security/using-your-existing-identity-management-system-with-google-cloud-platform
When creating a secure container image, which two items should you incorporate into the build if possible? (Choose two.)
Correct Answer:
BC
🗳️
Reference:
https://cloud.google.com/solutions/best-practices-for-building-containers