GCP Professional Cloud Security Engineer Practice Question

An investment bank runs several Google Cloud projects that store European customer PII. Auditors require that any interactive access by Google personnel to these projects be blocked until the bank's security-operations (SecOps) group explicitly grants just-in-time approval, and that every such event be logged for later review. Routine automated service operations performed by Google must continue without interruption. Which solution best meets these requirements while minimizing operational overhead?

  • Disable all Google-managed service accounts with an organization policy and encrypt all data with customer-supplied encryption keys (CSEK) to prevent Google from accessing data without the bank's intervention.

  • Enable Access Approval at the organization level, assign the SecOps Google Group the Access Approval Approver IAM role, and rely on the built-in Access Transparency logs for auditability.

  • Create a VPC Service Controls perimeter around the projects and deploy a Cloud Function that automatically approves or rejects access requests based on tags supplied by Google support.

  • Enable only Access Transparency on each project so that any Google access is logged, and periodically review the logs for unauthorized activity.

GCP Professional Cloud Security Engineer
Supporting compliance requirements
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot