Professional Cloud Security EngineerConfiguring access within a cloud solution environmentMedium

A financial institution is implementing a new application on Google Cloud that processes highly sensitive customer data. Due to regulatory requirements, all access to this data by Google support personnel must be explicitly approved by the institution's security team. This approval process must generate an audit trail. Which Google Cloud feature is designed to meet this specific requirement?

  1. AAccess Approval
  2. BOrganization Policy Constraints
  3. CData Loss Prevention (DLP)
  4. DVPC Service Controls
Show answer & explanation

Correct answer: A. Access Approval

Google Cloud Access Approval is specifically designed to meet regulatory requirements that mandate explicit customer approval for Google support and engineering access to customer data. It provides a granular approval workflow and an immutable audit trail.

Why the other options are wrong

  • B. Organization Policy Constraints enforce rules across resources but do not manage the approval of Google's internal access requests.
  • C. Data Loss Prevention (DLP) identifies and redacts sensitive data but does not control who accesses it or provide an approval process for Google personnel.
  • D. VPC Service Controls create security perimeters to prevent data exfiltration but do not manage or audit Google personnel access.

Google Cloud Access Approval

Access Approval allows customers to explicitly approve or deny Google support and engineering access to their Google Cloud data, generating an audit trail for compliance.

  • Mandates customer approval for Google access.
  • Provides an immutable audit trail.
  • Crucial for highly regulated industries like finance.

Memory trick: Approve access for Google, or it's a no-go.

More Configuring access within a cloud solution environment questions