Professional Cloud Security EngineerEnsuring complianceEasy

A financial institution is deploying a critical application on Google Cloud that must comply with strict regulatory requirements regarding data access and auditability. They need to ensure that Google support personnel only access their data with explicit, time-bound approval, and that all such access is fully logged and auditable. Which Google Cloud service should they implement to meet these requirements?

  1. ASecurity Command Center Premium
  2. BCloud Audit Logs
  3. CAccess Approval
  4. DVPC Service Controls
Show answer & explanation

Correct answer: C. Access Approval

Access Approval allows customers to explicitly approve or deny Google support and engineering access to their data or systems. This service provides the necessary auditable logs for compliance.

Why the other options are wrong

  • A. Security Command Center Premium provides threat detection and vulnerability management but not the explicit approval of Google personnel access.
  • B. Cloud Audit Logs record administrative activities and data access, but Access Approval is the mechanism that grants or denies the access itself.
  • D. VPC Service Controls protect against data exfiltration but do not manage explicit access by Google personnel.

Access Approval

A Google Cloud service that requires explicit customer approval before Google support and engineering can access customer data or systems.

  • Provides granular control over Google personnel access.
  • Generates auditable logs of all access requests and approvals.
  • Essential for strict compliance and regulatory environments.

Memory trick: Approve access, then the Google door opens.

More Ensuring compliance questions