Professional Cloud Security EngineerManaging operationsHard

A global media company uses Google Cloud Storage buckets to host static content for its websites. They have a strict compliance requirement to ensure that all Cloud Storage buckets are encrypted with customer-managed encryption keys (CMEK) and that public access is explicitly disabled. They need a continuous, automated way to assess compliance against these specific requirements across all their projects and receive alerts for any deviations. Which Google Cloud service should they use?

  1. AEvent Threat Detection with custom detectors
  2. BSecurity Health Analytics (SHA) with custom modules
  3. CCloud Monitoring custom metrics and alerting policies
  4. DCloud Audit Logs with custom BigQuery queries
Show answer & explanation

Correct answer: B. Security Health Analytics (SHA) with custom modules

Security Health Analytics (SHA) is designed to continuously scan Google Cloud resources for security misconfigurations and compliance violations. While it has built-in detectors, custom modules allow defining specific compliance checks, such as requiring CMEK for Cloud Storage and disabling public access, and then generating findings in Security Command Center for alerting.

Why the other options are wrong

  • A. Event Threat Detection focuses on behavioral threats from logs, not on scanning resource configurations for compliance.
  • C. Cloud Monitoring focuses on resource metrics and logs, not directly on assessing security configuration compliance against predefined policies.
  • D. Cloud Audit Logs can provide the data, but manual queries are not a continuous, automated assessment with alerts.

Security Health Analytics (SHA) Custom Modules

An extension of Security Health Analytics that allows users to define custom security checks and compliance policies for Google Cloud resources beyond the built-in detectors, generating findings in Security Command Center for deviations.

  • Extends SHA's capabilities for specific compliance needs.
  • Allows defining custom rules for resource configurations.
  • Continuously scans resources against defined policies.
  • Generates findings in Security Command Center for non-compliance.

Memory trick: SHA with Custom Modules is your 'compliance auditor', checking every 'resource' against your 'special rules'.

More Managing operations questions