GCP Professional Cloud Security Engineer Practice Question

Your company operates over 150 Google Cloud projects in a single organization. The security operations team must centrally activate Security Command Center (SCC) so they can manage detectors, create mute rules, and view findings across all projects. Individual application teams should have read-only visibility into findings limited to their own projects. What is the most efficient way to configure SCC and IAM to meet these requirements?

  • Enable SCC Premium separately in each project using automation. Grant the security operations team the Security Center Admin role on every project and let application teams inherit Viewer permissions from the organization.

  • Enable SCC Premium at the organization level. Grant the security operations team the Project Owner role on all projects and grant application teams the Security Center Source Admin role at the organization level.

  • Enable SCC Premium at the organization level. Grant the security operations team the Security Center Admin role at the organization level, and grant each application team the Security Center Findings Viewer role on only their respective projects.

  • Enable the SCC Standard tier in every project. Grant the security operations team the Logging Admin role at the organization level and grant application teams the Logging Viewer role on their projects.

GCP Professional Cloud Security Engineer
Managing operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot