Professional Cloud Security EngineerEnsuring complianceMedium

A healthcare provider is deploying a new application that processes sensitive patient data. They need to ensure that Google Cloud support personnel can only access this data after explicit, time-bound approval from their security team, and all access attempts are logged and auditable. Which Google Cloud service should they implement to meet this stringent requirement?

  1. ACloud Audit Logs
  2. BAccess Approval
  3. CAccess Transparency
  4. DData Loss Prevention (DLP)
Show answer & explanation

Correct answer: B. Access Approval

Access Approval allows customers to explicitly approve or deny access requests from Google support and engineering personnel to their data and configurations, providing a crucial layer of control for highly sensitive environments. It also logs all requests and approvals for auditability.

Why the other options are wrong

  • A. Cloud Audit Logs records administrative activities and data access, but is a logging service, not an approval mechanism.
  • C. Access Transparency provides detailed logs of Google Cloud personnel's administrative actions, but does not allow explicit approval/denial.
  • D. Data Loss Prevention (DLP) helps discover, classify, and protect sensitive data, but does not control Google personnel access.

Access Approval

A Google Cloud service that enables customers to explicitly approve or deny Google support and engineering access to their data and configurations.

  • Provides granular control over Google personnel access.
  • Generates audit logs for all access requests and approvals.
  • Integrates with existing approval workflows.

Memory trick: Access Approval is like a 'VIP Pass' system – Google staff need your explicit OK to enter.

More Ensuring compliance questions