GCP Professional Cloud Security Engineer Practice Question

Your organization processes EU personal data in several Google Cloud projects. You have already enabled Access Transparency and export all Cloud Audit Logs. Compliance demands that: (1) every request by Google personnel to access these projects must be explicitly approved by a designated security officer, (2) access must never occur without such approval, even during outages, and (3) each decision must be auditable. You propose enabling Access Approval. How should you respond to address these requirements?

  • Configure Access Approval to require two approvers and set the approval window to 24 hours; any access lacking dual approval will be automatically denied.

  • Enable Access Approval at the organization level and list the security officer as the sole approver; this configuration meets all three compliance requirements.

  • Explain that while Access Approval will provide explicit approvals and auditable records, Google can still self-approve access in rare emergencies, so requirement 2 cannot be fully guaranteed.

  • Recommend using Assured Workloads instead, because Access Approval cannot be enabled at the project level and therefore cannot cover all in-scope projects.

GCP Professional Cloud Security Engineer
Supporting compliance requirements
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot