GCP Professional Cloud Security Engineer Practice Question

Your company wants to trigger a Cloud Function whenever Security Command Center (SCC) reports a new HIGH-severity finding. You create a dedicated Pub/Sub topic in a central security project and configure an SCC notification with the filter severity="HIGH" that points to this topic. After deployment, no messages arrive on the topic and the function never runs. All APIs are enabled and the notification shows as active. Which change will allow SCC to publish findings to the topic?

  • Grant the Cloud Functions default runtime service account the Pub/Sub Publisher role on the destination topic.

  • Enable Data Access audit logs for securitycenter.googleapis.com in the project that owns the Pub/Sub topic.

  • Configure a Log Router sink that exports all security logs to the same Pub/Sub topic used by the Cloud Function.

  • Grant the SCC notifications service account ([email protected]) the Pub/Sub Publisher (roles/pubsub.publisher) role on the destination topic.

GCP Professional Cloud Security Engineer
Managing operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot