🔥 40% Off Crucial Exams Memberships — Deal ends today!

2 hours, 29 minutes remaining!

GCP Professional Cloud Security Engineer Practice Question

Your organization has activated Security Command Center (SCC) Premium across all production projects. The incident-response playbook states: "When a new HIGH or CRITICAL SCC finding is generated, page the security on-call engineer and immediately tag every affected Compute Engine VM with label environment=quarantine." The entire workflow must complete within 30 seconds, require no per-project agents, and follow least-privilege principles. Which architecture best meets these requirements?

  • Configure an organization-level SCC Pub/Sub notification for new findings; create a Cloud Function triggered by this topic that labels each listed VM with environment=quarantine using a least-privileged service account; create a log-based metric filtering findings with severity>=HIGH and a Cloud Monitoring alerting policy that pages the on-call team.

  • Install an agent on every production VM that watches the local serial console for SCC findings, applies the label when needed, and writes a log entry that is relayed to PagerDuty through Pub/Sub.

  • Enable Eventarc to forward SCC findings to a Cloud Run service that adds the quarantine label and sends pager alerts by calling the Stackdriver Monitoring API.

  • Deploy a Cloud Scheduler job that polls the SCC API every minute, writes all HIGH or CRITICAL findings to Cloud Storage, and triggers a Cloud Function via a Cloud Storage event to label the affected VMs and send an email alert.

GCP Professional Cloud Security Engineer
Managing operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot