🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 51 minutes remaining!

GCP Professional Cloud Security Engineer Practice Question

Your organization uses Security Command Center (SCC) Premium. Compliance requires that any Cloud Storage bucket in production projects be flagged in Security Health Analytics (SHA) if its IAM policy grants objectViewer or objectReader access to either "allUsers" or "allAuthenticatedUsers." You need an automated, code-reviewable solution that generates a SHA finding whenever such a bucket exists. Which approach satisfies these requirements?

  • Enable the organization policy constraint constraints/storage.publicAccessPreventionEnforced and rely on SCC to automatically raise SHA findings when the constraint is violated.

  • Deploy Policy Controller with an OPA Gatekeeper constraint that denies any bucket whose IAM policy contains allUsers or allAuthenticatedUsers, and store the constraint template YAML in the Git repository.

  • Create a custom Event Threat Detection rule that filters Cloud Audit Logs for storage.buckets.setIamPolicy calls granting public access and send alerts to the security team.

  • Commit a YAML file defining a Security Health Analytics custom module with a resourceSelector of storage.googleapis.com/Bucket and a CEL predicate that checks the bucket's IAM bindings for allUsers or allAuthenticatedUsers; deploy it organization-wide with gcloud scc custom-modules create.

GCP Professional Cloud Security Engineer
Managing operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot