☎  076 959 6407✉  support@quizcrazepro.co.za
Learn. Practice. Build your future.
BlogHelpContact
G

Google Professional Cloud Security Engineer Actual Exam Questions

318 Questions120 Minutes70% Passing Score▣ Updated: Sep 2026

Question 222 of 318

Single answer
Your organization wants to protect all workloads that run on Compute Engine VM to ensure that the instances weren't compromised by boot-level or kernel-level malware. Also, you need to ensure that data in use on the VM cannot be read by the underlying host system by using a hardware-based solution. What should you do?
A1. Use Google Shielded VM including secure boot, Virtual Trusted Platform Module (vTPM), and integrity monitoring.
2. Create a Cloud Run function to check for the VM settings, generate metrics, and run the function regularly.
B1. Activate Virtual Machine Threat Detection in Security Command Center (SCC) Premium.
2. Monitor the findings in SCC.
C1. Use Google Shielded VM including secure boot, Virtual Trusted Platform Module (vTPM), and integrity monitoring.
2. Activate Confidential Computing.
3. Enforce these actions by using organization policies.
D1. Use secure hardened images from the Google Cloud Marketplace.
2. When deploying the images, activate the Confidential Computing option.
3. Enforce the use of the correct images and Confidential Computing by using organization policies.
Correct Answer: C

1. Use Google Shielded VM including secure boot, Virtual Trusted Platform Module (vTPM), and integrity monitoring.<br> 2. Activate Confidential Computing.<br> 3. Enforce these actions by using organization policies.

Explanation

The correct answer is highlighted above. Review the wording carefully, then use the next question to continue building your understanding of Google certification topics.

About this practice exam

Review 318 Google questions with answers and explanations. Use the navigation to move through the exam at your own pace.