nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #13

An organization's security and risk management teams are concerned about where their responsibility lies for certain production workloads they are running in Google Cloud Platform (GCP), and where…

The correct answer is B. Defending against XSS and SQLi attacks. In PaaS the customer is responsible for web app security, deployment, usage, access policy, and https://cloud.google.com/architecture/framework/security/shared-responsibility-shared-fate

Submitted by hassan_iq· Apr 18, 2026Ensuring data protection

Question

An organization's security and risk management teams are concerned about where their responsibility lies for certain production workloads they are running in Google Cloud Platform (GCP), and where Google's responsibility lies. They are mostly running workloads using Google Cloud's Platform-as-a-Service (PaaS) offerings, including App Engine primarily. Which one of these areas in the technology stack would they need to focus on as their primary responsibility when using App Engine?

Options

  • AConfiguring and monitoring VPC Flow Logs
  • BDefending against XSS and SQLi attacks
  • CManage the latest updates and security patches for the Guest OS
  • DEncrypting all stored data

How the community answered

(34 responses)
  • B
    94% (32)
  • C
    3% (1)
  • D
    3% (1)

Explanation

In PaaS the customer is responsible for web app security, deployment, usage, access policy, and https://cloud.google.com/architecture/framework/security/shared-responsibility-shared-fate

Topics

#Shared Responsibility Model#PaaS#Application Security#Web Application Vulnerabilities

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice