Professional Cloud Security EngineerEnsuring complianceMedium
A healthcare provider is deploying a new application that processes sensitive patient data. They need to ensure that Google Cloud support personnel can only access this data after explicit, time-bound approval from their security team, and all access attempts are logged and auditable. Which Google Cloud service should they implement to meet this stringent requirement?
- ACloud Audit Logs
- BAccess Approval
- CAccess Transparency
- DData Loss Prevention (DLP)
Show answer & explanationAnswer & explanation
Correct answer: B. Access Approval
Access Approval allows customers to explicitly approve or deny access requests from Google support and engineering personnel to their data and configurations, providing a crucial layer of control for highly sensitive environments. It also logs all requests and approvals for auditability.
Why the other options are wrong
- A. Cloud Audit Logs records administrative activities and data access, but is a logging service, not an approval mechanism.
- C. Access Transparency provides detailed logs of Google Cloud personnel's administrative actions, but does not allow explicit approval/denial.
- D. Data Loss Prevention (DLP) helps discover, classify, and protect sensitive data, but does not control Google personnel access.
Access Approval
A Google Cloud service that enables customers to explicitly approve or deny Google support and engineering access to their data and configurations.
- Provides granular control over Google personnel access.
- Generates audit logs for all access requests and approvals.
- Integrates with existing approval workflows.
Memory trick: Access Approval is like a 'VIP Pass' system – Google staff need your explicit OK to enter.