🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 52 minutes remaining!

GCP Professional Cloud Security Engineer Practice Question

Your security team must detect any Cloud Storage buckets across hundreds of projects in your organization that do not have uniform bucket-level access (UBLA) enabled. The built-in Security Health Analytics (SHA) detectors do not cover this control. Security Command Center Premium is already activated at the organization level. What should you do to implement this control in a way that runs automatically and produces findings centrally for all projects?

  • Set the Organization Policy constraint constraints/storage.uniformBucketLevelAccess to enforced: TRUE; SHA will automatically generate findings when this policy is violated.

  • In the Security Command Center console, enable the built-in Legacy Storage IAM Binding detector and add a custom condition for UBLA.

  • Author a Security Health Analytics custom module in YAML that selects the asset type storage.googleapis.com/Bucket and contains a CEL rule flagging buckets where resource.uniformBucketLevelAccess.enabled == false, then deploy the module at the organization level with gcloud scc custom-modules create.

  • Create an Event Threat Detection custom alert policy that evaluates Cloud Storage bucket metadata with a CEL rule and enable it in each project.

GCP Professional Cloud Security Engineer
Managing operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot