Professional Cloud Security EngineerManaging operationsMedium

A company is using Security Command Center (SCC) Premium. They want to ensure that any new or existing Cloud Storage bucket that is publicly accessible is immediately flagged as a high-priority finding. They also need to ensure that their security team is notified via email within minutes of such a finding. How should they configure Security Command Center and Cloud Monitoring to achieve this?

  1. AEnable Security Health Analytics, create a custom module to detect public buckets, and configure a Cloud Monitoring alert policy on the custom module's metric.
  2. BEnsure Security Health Analytics is enabled, which includes a built-in detector for public Cloud Storage buckets, and create a Cloud Monitoring alert policy based on the 'public_bucket_acl' finding in SCC.
  3. CCreate a custom log sink for Cloud Storage access logs to BigQuery and set up a scheduled query in BigQuery to email the security team for public buckets.
  4. DSet up Event Threat Detection to analyze Cloud Audit Logs for 'storage.buckets.setIamPolicy' operations and configure an alert policy in Cloud Monitoring.
Show answer & explanation

Correct answer: B. Ensure Security Health Analytics is enabled, which includes a built-in detector for public Cloud Storage buckets, and create a Cloud Monitoring alert policy based on the 'public_bucket_acl' finding in SCC.

Security Health Analytics (SHA), part of SCC Premium, has a built-in detector for publicly accessible Cloud Storage buckets ('public_bucket_acl'). Once enabled, SHA will generate findings. A Cloud Monitoring alert policy can then be configured to trigger email notifications based on these specific SCC findings.

Why the other options are wrong

  • A. While custom modules can detect public buckets, SHA already has a built-in detector for this common misconfiguration, making a custom module unnecessary and less efficient.
  • C. This approach is overly complex, requires significant custom development, and would not provide 'within minutes' notification compared to direct integration between SCC findings and Cloud Monitoring alerts.
  • D. Event Threat Detection (ETD) focuses on active threats from logs, not continuous posture assessment for misconfigurations like public buckets. Analyzing `setIamPolicy` might detect policy changes, but SHA directly reports the *state* of public accessibility.

SCC Findings to Cloud Monitoring Alerts

Security Command Center findings, including those from Security Health Analytics, can be exported to Cloud Monitoring as metrics, allowing for the creation of alert policies for real-time notifications.

  • SCC findings automatically appear in Cloud Monitoring.
  • Built-in SHA detectors cover common misconfigurations.
  • Cloud Monitoring alert policies can be based on SCC finding metrics.
  • Enables timely notification for critical security posture issues.

Memory trick: SCC finds the issue, Monitoring makes the alert ring loud and clear.

More Managing operations questions