Professional Cloud Security EngineerManaging operationsMedium
A retail company is expanding its online presence and needs to ensure that its public-facing web applications comply with PCI DSS requirements. Specifically, they need to regularly assess their Google Cloud environment for misconfigurations that could lead to data breaches, such as publicly exposed storage buckets or overly permissive IAM roles on critical resources. Which Security Command Center service is best suited for this continuous compliance and misconfiguration assessment?
- AContainer Threat Detection
- BWeb Security Scanner
- CEvent Threat Detection
- DSecurity Health Analytics
Show answer & explanationAnswer & explanation
Correct answer: D. Security Health Analytics
Security Health Analytics (SHA) is specifically designed to identify security misconfigurations and compliance violations across Google Cloud resources. It continuously scans for issues like publicly exposed storage buckets, overly permissive IAM roles, and other deviations from security best practices, making it ideal for PCI DSS compliance assessments.
Why the other options are wrong
- A. Container Threat Detection focuses on runtime threats within containerized environments, not general cloud resource misconfigurations.
- B. Web Security Scanner focuses on vulnerabilities within web applications themselves, not cloud resource misconfigurations.
- C. Event Threat Detection analyzes logs for suspicious activity and threats, not for continuous misconfiguration assessment.
Security Health Analytics (SHA)
Security Health Analytics is a Security Command Center service that continuously scans your Google Cloud assets for security misconfigurations, vulnerabilities, and compliance violations. It provides findings related to IAM, networking, storage, and other services.
- Continuously assesses cloud resource configurations.
- Identifies misconfigurations and compliance issues.
- Integrated with Security Command Center.
Memory trick: Health Analytics checks config for compliance.