Professional Cloud Security EngineerEnsuring data protectionHard
A compliance team needs to verify that all Google Cloud Storage buckets in their organization have a uniform bucket-level access policy enabled to simplify permissions management and prevent object ACLs from overriding bucket-level policies. They want to automate the detection of non-compliant buckets. Which Google Cloud service should they use?
- ACloud Monitoring with custom metrics
- BCloud Audit Logs with BigQuery export
- CCloud Asset Inventory with Security Health Analytics
- DData Loss Prevention (DLP) scans
Show answer & explanationAnswer & explanation
Correct answer: C. Cloud Asset Inventory with Security Health Analytics
Cloud Asset Inventory provides a centralized inventory of all Google Cloud assets. Security Health Analytics, a service within Security Command Center, can be configured to detect misconfigurations, including whether uniform bucket-level access is enabled or disabled for Cloud Storage buckets. This combination allows for automated compliance checks against security policies.
Why the other options are wrong
- A. Cloud Monitoring focuses on operational metrics and logs, not directly on evaluating resource configuration states against compliance policies.
- B. Cloud Audit Logs record API calls and administrative actions, which can indicate changes, but it doesn't provide an automated way to continuously check the current state of all buckets against a policy for compliance without significant custom development.
- D. DLP scans content for sensitive data, it does not assess infrastructure configurations like bucket access policies.
Cloud Asset Inventory & Security Health Analytics for Compliance
Using Cloud Asset Inventory to discover cloud resources and Security Health Analytics to continuously evaluate their configurations against security policies and compliance requirements.
- Cloud Asset Inventory provides a comprehensive resource inventory.
- Security Health Analytics detects misconfigurations and vulnerabilities.
- Automates compliance checks for resource settings.
Memory trick: Asset Inventory sees all, Security Health Analytics checks the wall.