GCP Professional Cloud Security Engineer Practice Question
Your organization pioneers a self-service project factory where hundreds of Google Cloud projects are created every month. You previously enabled Security Command Center (SCC) Premium and Security Health Analytics (SHA) on a handful of existing projects, but recent penetration-test results show that brand-new projects can still contain publicly readable Cloud Storage buckets that were never flagged by SHA. You must ensure that SHA automatically analyzes every current and future project for misconfigurations without adding manual onboarding steps or custom code. What should you do?
Configure an aggregated log sink for Admin Activity audit logs and write BigQuery scheduled queries that search for public bucket indicators in every project.
Keep SCC enabled per project but create an Automation that runs gcloud scc settings update in Cloud Build whenever a new project is provisioned.
Deploy a Cloud Function subscribed to Cloud Pub/Sub that calls the SHA API to scan a project each time a new Cloud Storage bucket is created.
Enable Security Command Center with Security Health Analytics at the organization root, letting the service inherit across all existing and newly created projects.
When SCC (Standard or Premium) is activated at the organization or folder level, every descendant project-present and future-is automatically onboarded. Enabling Security Health Analytics as part of SCC at that higher level ensures its built-in detectors (including PUBLIC_BUCKET_ACL and PUBLIC_BUCKET_POLICY) continuously scan all projects for risky configurations. Enabling SCC only in individual projects, writing custom Cloud Functions, or relying solely on log exports leaves gaps because new projects are not covered until they are explicitly configured, so findings will be missed.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What does enabling Security Command Center (SCC) at the organization root do?
Open an interactive chat with Bash
What is Security Health Analytics (SHA) and how does it work?
Open an interactive chat with Bash
Why is manual onboarding or custom code insufficient in this scenario?
Open an interactive chat with Bash
What is Security Command Center (SCC) in Google Cloud?
Open an interactive chat with Bash
How does Security Health Analytics (SHA) detect publicly readable Cloud Storage buckets?
Open an interactive chat with Bash
Why is enabling SCC at the organization root better than project-level activation?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Managing operations
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .