Professional Cloud Security EngineerEnsuring complianceMedium

A financial institution is deploying a highly regulated application on Google Cloud. They need to ensure that no Google support personnel can ever access their sensitive data, even in emergency situations, without explicit, auditable approval from the financial institution. Which Google Cloud service directly addresses this specific requirement?

  1. AVPC Service Controls
  2. BAccess Transparency
  3. CAccess Approval
  4. DData Loss Prevention (DLP)
Show answer & explanation

Correct answer: C. Access Approval

Access Approval provides a mechanism for customers to explicitly approve or deny Google personnel access to their data and configurations. It generates audit logs for every access request and decision, ensuring transparency and control.

Why the other options are wrong

  • A. VPC Service Controls creates security perimeters to prevent data exfiltration, not to control Google personnel access.
  • B. Access Transparency provides logs of Google personnel's administrative actions, but doesn't allow customers to approve/deny access.
  • D. Data Loss Prevention (DLP) identifies and redacts sensitive data, but doesn't manage Google personnel access permissions.

Access Approval

Access Approval allows Google Cloud customers to explicitly approve or deny Google personnel access to their data and configurations, providing an auditable workflow for sensitive operations.

  • Requires customer approval for Google personnel access.
  • Generates audit logs of all access requests and decisions.
  • Enhances control and transparency over data access by Google.

Memory trick: Access Approval is like a 'gatekeeper' for Google, only opening with your 'OK'.

More Ensuring compliance questions