GCP Professional Cloud Security Engineer Practice Question
Your company uses Security Command Center (SCC) Premium and wants an automated control that raises High-severity findings whenever any Cloud Storage bucket in production projects does not have uniform bucket-level access (UBLA) enabled. The policy definition must be version-controlled as code, first tested in a development project, and then rolled out across the entire organization with minimal ongoing maintenance. What should you do?
Enable the built-in Storage Public Access Prevention detector in Security Health Analytics and change its severity to High so it will also report buckets lacking UBLA.
Apply the constraints/storage.publicAccessPrevention=ENFORCED organization policy and rely on Policy Denied audit logs in SCC to identify any production bucket that lacks UBLA.
Configure an Event Threat Detection (ETD) custom rule that inspects Cloud Audit Logs for storage.setIamPermissions calls without UBLA and export these logs to SCC as High-severity findings.
Create a Security Health Analytics custom module defined in a YAML file that uses a CEL expression to flag buckets where uniformBucketLevelAccess is disabled; test it in a development project, then deploy it organization-wide with gcloud scc custom-modules sha create, setting the severity to High.
Security Health Analytics (SHA) in SCC lets you create custom modules that evaluate assets against rules written in YAML and Common Expression Language (CEL). By authoring a custom module whose CEL condition tests resource.data.iamConfiguration.uniformBucketLevelAccess.enabled == false, you can assign a High severity, store the YAML file in source control, validate it in a development project, and then promote it by running gcloud scc custom-modules sha create (or update) at the organization level. SHA automatically scans all current and new buckets and surfaces non-compliant ones as findings. The other options do not meet requirements:
Event Threat Detection cannot be configured with ad-hoc rules on Cloud Storage configuration; it analyzes security-relevant log events, not resource state.
No built-in SHA detector checks for UBLA, so simply enabling an existing rule and changing severity will not capture this condition.
Enforcing the constraints/storage.publicAccessPrevention organization policy controls a different setting and blocks future misconfigurations but does not generate High-severity SCC findings for existing buckets or allow rule logic to live in source control.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is uniform bucket-level access (UBLA) in Cloud Storage?
Open an interactive chat with Bash
What is Common Expression Language (CEL) used for in Security Health Analytics custom modules?
Open an interactive chat with Bash
How does Security Health Analytics enable organization-wide monitoring for security rules?
Open an interactive chat with Bash
What is Security Health Analytics (SHA) in SCC?
Open an interactive chat with Bash
What is uniform bucket-level access (UBLA) for Cloud Storage?
Open an interactive chat with Bash
What is Common Expression Language (CEL), and why is it used in SHA custom modules?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Managing operations
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .