nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #269

Your organization has an operational image classification model running on a managed AI service on Google Cloud. You are in a configuration review with stakeholders and must describe the security…

The correct answer is C. Explain Google's shared responsibility model. Focus the configuration review on Identity and. When using a managed AI service (which is a PaaS offering), Google is responsible for securing the underlying infrastructure, hypervisor, and service runtime. The customer retains responsibility for identity and access management, data classification, input/output controls, and…

Submitted by valeria.br· Apr 18, 2026Configuring access within a cloud solution environment

Question

Your organization has an operational image classification model running on a managed AI service on Google Cloud. You are in a configuration review with stakeholders and must describe the security responsibilities for the image classification model. What should you do?

Options

  • AExplain that using platform-as-a-service (PaaS) transfers security concerns to Google. Describe
  • BExplain the security aspects of the code that transforms user-uploaded images using Google's
  • CExplain Google's shared responsibility model. Focus the configuration review on Identity and
  • DExplain the development of custom network firewalls around the image classification service for

How the community answered

(25 responses)
  • A
    8% (2)
  • C
    88% (22)
  • D
    4% (1)

Explanation

When using a managed AI service (which is a PaaS offering), Google is responsible for securing the underlying infrastructure, hypervisor, and service runtime. The customer retains responsibility for identity and access management, data classification, input/output controls, and model configuration. The correct approach in a configuration review is to explain Google's shared responsibility model and then focus the discussion on the areas the customer owns - primarily IAM policies and access controls for the model. Option A is incorrect because PaaS does not transfer all security responsibilities to Google; the customer still owns data governance and access control. Options B and D address narrow or infrastructure-level concerns that are largely Google's responsibility in a PaaS model.

Topics

#Shared Responsibility Model#Cloud Security Governance#Identity and Access Management (IAM)#Managed Services Security

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice