Professional Cloud Security EngineerManaging operationsHard

A security engineer needs to configure Cloud Monitoring to alert them if any of their Google Cloud resources become non-compliant with a specific custom security standard. The custom standard checks for the presence of unencrypted Cloud Storage buckets and public IP addresses on Compute Engine instances. The alerts should be triggered when a resource transitions from compliant to non-compliant. Which service within Security Command Center should be used to define and monitor this custom standard?

  1. ASecurity Health Analytics (SHA) custom modules
  2. BWeb Security Scanner (WSS)
  3. CContainer Threat Detection (CTD)
  4. DEvent Threat Detection (ETD)
Show answer & explanation

Correct answer: A. Security Health Analytics (SHA) custom modules

Security Health Analytics (SHA) custom modules allow users to define their own security standards and detectors for Google Cloud resources. These custom modules can then be integrated with Cloud Monitoring to trigger alerts when a resource violates the custom standard (e.g., an unencrypted bucket).

Why the other options are wrong

  • B. WSS scans web applications for vulnerabilities, not general cloud resource compliance.
  • C. CTD monitors runtime threats in containers, not compliance of general cloud resources.
  • D. ETD focuses on detecting active threats from logs, not continuous compliance monitoring against custom standards.

Security Health Analytics (SHA) Custom Modules

A feature of Security Health Analytics that allows users to define custom security checks and compliance standards for their Google Cloud resources, extending SHA's built-in detectors.

  • Define custom security compliance rules.
  • Checks for resource misconfigurations.
  • Integrates with Security Command Center and Cloud Monitoring.
  • Enables monitoring against organization-specific standards.

Memory trick: SHA custom modules tailor the health checks to your rules.

More Managing operations questions