🔥 40% Off Crucial Exams Memberships — Deal ends today!

44 minutes, 42 seconds remaining!

GCP Professional Cloud Security Engineer Practice Question

Your organization recently enabled Security Command Center (SCC) Premium at the organization level. You must ensure that any Cloud Storage bucket that becomes publicly accessible in any existing or future project is detected. When a HIGH-severity finding of this type appears, it has to be sent immediately to an existing Pub/Sub topic that feeds the corporate SIEM. Security analysts must be able to acknowledge or mute the finding in SCC, but they must not be able to change bucket configurations. Which combination of actions will meet these requirements with the least ongoing operational effort?

  • Configure a Cloud Asset Inventory feed for resource type storage.googleapis.com/Bucket with a condition that matches public IAM policies, export the feed to the Pub/Sub topic, and give the analyst group roles/cloudasset.viewer so they can mark resources as compliant once fixed.

  • Enable Event Threat Detection, create a log sink that exports storage.setIamPolicy Cloud Audit Logs to the Pub/Sub topic, and grant the analyst group the IAM role roles/storage.admin so they can investigate and resolve findings.

  • Enable SCC Standard in every project, configure a project-level notification configuration that filters on category="PUBLIC_BUCKET_ACL", and grant the analyst group the roles/owner role on each project so they can acknowledge findings.

  • Enable Security Health Analytics in SCC at the organization level, create an organization-level notification configuration that filters on severity="HIGH" AND category="BUCKET_IAM_PUBLICLY_ACCESSIBLE" and sends findings to the SIEM Pub/Sub topic, and grant the analyst group the IAM role roles/securitycenter.findingsEditor on the organization.

GCP Professional Cloud Security Engineer
Managing operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot