|
via Udemy |
Go to Course: https://www.udemy.com/course/professional-cloud-security-engineer-exam-questions-questions/
Google Cloud Professional Cloud Security Engineer CertificationCourse DescriptionA Cloud Security Engineer allows organizations to design and implement secure workloads and infrastructure on Google Cloud. Through an understanding of security best practices and industry requirements, this individual designs, develops, and manages a secure solution by using Google security technologies. A Cloud Security Engineer is procient in Identity and Access Management, dening the resource hierarchy and policies, using Google Cloud technologies to provide data protection, conguring network security defenses, monitoring environments for threats, conguring security automation, securing AI workloads, securing the soware supply chain, and enforcing regulatory controls.What You'll LearnImplement identity and access management (IAM) strategies to control resource accessApply network security best practices using VPCs, firewall rules, and private connectivityEncrypt data at rest and in transit using Cloud KMS, CMEK, and DLP servicesMonitor and respond to threats using Security Command Center, audit logs, and third-party toolsManage regulatory compliance and risk through policy enforcement and secure configurationsRequirementsExperience with GCP services such as Compute Engine, Cloud Storage, and IAMBasic understanding of cloud networking, authentication, and security modelsFamiliarity with Linux command-line tools and scripting is helpfulAccess to a Google Cloud account for hands-on practice and labsWho This Course Is ForCloud engineers, architects, and security professionals working with GCPIndividuals preparing for the Google Cloud Professional Cloud Security Engineer certification examDevOps and SecOps professionals securing infrastructure and applications in cloud environmentsIT professionals expanding into cloud security and compliance rolesSection 1: Configuring Access (~25%)1.1 Managing Cloud IdentityConfigure Google Cloud Directory Sync and implement single sign-on (SSO) with third-party identity providersManage super administrator accountsAutomate user lifecycle managementAdminister user accounts and groups programmaticallyConfigure Workforce Identity Federation1.2 Managing Service AccountsSecure and protect service accounts, including default accountsIdentify when to use service accountsCreate, disable, and authorize service accountsSecure, audit, and manage service account keysManage short-lived credentialsConfigure Workload Identity FederationManage service account impersonation1.3 Managing AuthenticationDefine password and session management policiesSet up SAML and OAuthConfigure and enforce 2-step verification1.4 Managing and Implementing Authorization ControlsManage IAM roles, permissions, and separation of dutiesConfigure IAM and ACL permissionsUse IAM conditions and deny policies to manage permissionsApply least privilege across organization, folder, project, and resource levelsConfigure Access Context ManagerApply Policy Intelligence recommendationsManage permissions through groupsConfigure Privileged Access Manager and identify use cases1.5 Defining the Resource HierarchyManage folders and projects at scaleApply organization policies (pre-built and custom) at different hierarchy levelsUse the resource hierarchy for permission inheritanceSection 2: Securing Communications and Establishing Boundary Protection (~22%)2.1 Designing and Configuring Perimeter SecurityConfigure network perimeter controls (Cloud NGFW, IAP, load balancers, Certificate Authority Service)Enable application layer inspection (Layer 7) on Cloud NGFWDifferentiate between public and private IP addressingConfigure web application firewalls (Google Cloud Armor)Deploy Secure Web ProxyConfigure Cloud DNS security settingsMonitor and restrict configured APIs2.2 Configuring Boundary SegmentationConfigure security settings for VPC networks, peering, Shared VPC, and firewall rulesConfigure network isolation and data encapsulation for N-tier applicationsIdentify use cases and configure VPC Service Controls2.3 Establishing Private ConnectivitySet up private connectivity between VPC networks and GCP projectsConfigure HA VPN, Cloud Interconnect, and encryption for private connectivitySet up Private Google Access and Private Service ConnectUse Cloud NAT for outbound trafficSection 3: Ensuring Data Protection (~23%)3.1 Protecting Sensitive Data and Preventing Data LossConfigure Sensitive Data Protection (SDP) for PII discovery, redaction, pseudonymization, and format-preserving encryptionRestrict access to services like BigQuery, Cloud Storage, and Cloud SQLSecure secrets using Secret ManagerProtect and manage compute instance metadata3.2 Managing Encryption at Rest, in Transit, and in UseChoose between default encryption, CMEK, and Cloud EKMUse software and hardware encryption keys appropriatelyCreate, rotate, revoke, and import encryption keysApply encryption methods to use casesConfigure object lifecycle policies in Cloud StorageEnable Confidential Computing3.3 Securing AI WorkloadsApply security/privacy controls to protect AI/ML models and dataDefine requirements for IaaS- and PaaS-hosted model trainingSecure Vertex AI workloadsSection 4: Managing Operations (~19%)4.1 Automating Infrastructure and Application SecurityAutomate security scanning for CVEs in CI/CD pipelinesConfigure Binary Authorization for GKE and Cloud RunAutomate VM/container image creation and patchingManage policy drift detection and cloud security posture (e.g., Security Health Analytics, custom org policies/modules)4.2 Configuring Logging, Monitoring, and DetectionAnalyze logs: Cloud NGFW, VPC Flow Logs, Packet Mirroring, Cloud IDS, Log AnalyticsDesign a logging strategyMonitor, respond to, and remediate security incidentsDesign secure access to logsExport logs to external systemsConfigure Cloud Audit Logs and data access logsSet up log sinks and aggregated log exportsMonitor Security Command CenterSection 5: Supporting Compliance Requirements (~11%)5.1 Adhering to Regulatory and Industry StandardsDetermine technical needs across compute, data, network, and storageEvaluate Google Cloud's shared responsibility modelConfigure security controls to meet compliance (e.g., Assured Workloads, org policies, Access Transparency, Access Approval)Define which GCP resources fall within compliance scopeMap compliance requirements to GCP services and controls (e.g., access segmentation, audit logging)