GCP Professional Cloud Security Engineer Practice Question
Your company has activated Security Command Center (SCC) at the organization level using the Standard tier. Security operations now wants to be alerted within minutes when brute-force login attempts against Cloud SQL or suspicious IAM role-binding changes are detected. They prefer a built-in, fully managed capability rather than developing and maintaining custom log-based detections. What should you do to meet the requirement?
Deploy Cloud IDS, create custom log-based metrics for Cloud Audit Logs, and forward the alerts into SCC through Pub/Sub integration.
Upgrade Security Command Center to the Premium tier and enable Event Threat Detection so that its near-real-time findings appear automatically in SCC.
Enable Web Security Scanner in SCC Standard and schedule continuous scans to identify brute-force attempts and role-binding changes.
Remain on the Standard tier and configure Security Health Analytics to run hourly scans for Cloud SQL and IAM misconfigurations.
Near-real-time threat detections for activity such as brute-force attempts against Cloud SQL and anomalous IAM role changes are provided by the Event Threat Detection (ETD) service. ETD is a built-in component of Security Command Center's Premium tier and analyzes Cloud Audit Logs and VPC Flow Logs continuously, generating findings within minutes. ETD is not available in the Standard tier, and neither Security Health Analytics nor Web Security Scanner provide real-time threat detection for these scenarios. Building custom log-based metrics or integrating Cloud IDS would require significant ongoing rule creation and maintenance, contrary to the low-overhead requirement. Therefore, upgrading SCC to the Premium tier and enabling Event Threat Detection is the most appropriate solution.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Security Command Center (SCC)?
Open an interactive chat with Bash
What is Event Threat Detection (ETD)?
Open an interactive chat with Bash
How does Event Threat Detection differ from Security Health Analytics?
Open an interactive chat with Bash
What is Security Command Center (SCC)?
Open an interactive chat with Bash
What is Event Threat Detection (ETD) in SCC Premium?
Open an interactive chat with Bash
How does Event Threat Detection differ from Security Health Analytics?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Managing operations
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .