GCP Professional Cloud Security Engineer Practice Question
An investment bank runs several Google Cloud projects that store European customer PII. Auditors require that any interactive access by Google personnel to these projects be blocked until the bank's security-operations (SecOps) group explicitly grants just-in-time approval, and that every such event be logged for later review. Routine automated service operations performed by Google must continue without interruption. Which solution best meets these requirements while minimizing operational overhead?
Disable all Google-managed service accounts with an organization policy and encrypt all data with customer-supplied encryption keys (CSEK) to prevent Google from accessing data without the bank's intervention.
Enable Access Approval at the organization level, assign the SecOps Google Group the Access Approval Approver IAM role, and rely on the built-in Access Transparency logs for auditability.
Enable only Access Transparency on each project so that any Google access is logged, and periodically review the logs for unauthorized activity.
Create a VPC Service Controls perimeter around the projects and deploy a Cloud Function that automatically approves or rejects access requests based on tags supplied by Google support.
Access Approval allows customers to place an approval gate in front of any manual (human) access that Google support or engineering staff might need, while not affecting Google's automated system maintenance. Enabling Access Approval at the organization level automatically covers every current and future project unless individually overridden, reducing administrative effort. Granting the SecOps Google Group the predefined IAM role roles/accessapproval.approver lets its members approve or dismiss requests. Access Transparency is activated with Access Approval, ensuring that every provider access attempt and its customer decision are written to audit logs for compliance verification.
The other options do not meet all requirements:
Enabling only Access Transparency creates audit logs but does not block access pending approval.
VPC Service Controls address data exfiltration risks, not provider access, and custom functions cannot intercept Google personnel access.
Disabling Google-managed service accounts or using customer-supplied encryption keys would hinder essential automated maintenance and still would not provide an approve/deny workflow or full audit trail.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Access Approval in Google Cloud?
Open an interactive chat with Bash
What is the difference between Access Approval and Access Transparency?
Open an interactive chat with Bash
What is the role of `roles/accessapproval.approver` in Access Approval?
Open an interactive chat with Bash
What is Access Approval and how does it work?
Open an interactive chat with Bash
What is the difference between Access Transparency and Access Approval?
Open an interactive chat with Bash
Why is enabling Access Approval at the organization level better than at the project level?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Supporting compliance requirements
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .