GCP Professional Cloud Security Engineer Practice Question
Your healthcare enterprise must comply with a policy that any Google administrator access to protected health information (PHI) must be explicitly approved by your security team and later traceable in a single log stream together with regular Cloud Audit Logs. You have already turned on Access Approval for every in-scope project and designated a Google Group to receive approval requests. Which additional action best satisfies the policy requirement for an end-to-end auditable chain of provider access?
Enable Access Transparency for the organization and create an aggregated log sink that exports both Access Transparency and Cloud Audit Logs to your central logging project.
Deploy a Cloud Function that triggers on Access Approval Pub/Sub notifications and writes a custom record to BigQuery each time a request is granted.
Activate automated data inspection jobs in Cloud DLP for the log buckets that hold audit logs.
Place the projects inside a VPC Service Controls perimeter and enable dry-run mode to capture any violations.
Access Approval blocks Google personnel from accessing customer content until an approver grants the request, but it does not itself record the actions taken after approval. Access Transparency generates immutable log entries each time Google support or engineering staff access a customer resource and writes those entries to Cloud Logging alongside Admin Activity and Data Access audit logs. Exporting these logs through an aggregated sink lets the security team keep them with the rest of their compliance logs for long-term retention or analysis. VPC Service Controls, Cloud DLP, and ad-hoc Cloud Functions do not record provider access events and therefore cannot close the audit trail gap.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Access Transparency in GCP?
Open an interactive chat with Bash
What is an aggregated log sink in GCP, and why is it important for compliance?
Open an interactive chat with Bash
How does Access Transparency differ from Cloud Audit Logs in GCP?
Open an interactive chat with Bash
What is Access Transparency in Google Cloud?
Open an interactive chat with Bash
What is an aggregated log sink in Google Cloud?
Open an interactive chat with Bash
How does Access Approval work in Google Cloud?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Supporting compliance requirements
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .