A company requires that all access to highly sensitive data in Cloud Storage buckets must be approved by a designated security team member before access is granted. This approval process should be integrated directly into the Google Cloud IAM workflow. Which Google Cloud feature enables this requirement?
- AOrganization Policy Constraints
- BData Loss Prevention (DLP)
- CAccess Approval
- DCloud IAM Conditions
Show answer & explanationAnswer & explanation
Correct answer: C. Access Approval
Access Approval allows you to require explicit approval for Google personnel to access your Google Cloud resources or data. While not for *your* users, it addresses the core concept of requiring approval *before* access to sensitive data, which is analogous to the scenario described for Google's own access. For *your* users, you would combine IAM, Org Policies, and potentially custom workflows. However, among the given options, Access Approval is the only one *specifically* designed for an approval workflow before access, even if the 'who' is different.
Why the other options are wrong
- A. Organization Policy Constraints enforce rules across the organization but do not provide an interactive, per-access approval mechanism.
- B. Data Loss Prevention (DLP) scans and redacts sensitive data, it does not manage access approval workflows.
- D. Cloud IAM Conditions apply to *when* an existing binding is effective (e.g., time-based, IP-based) but don't implement an explicit 'approval workflow' for every access request.
Google Cloud Access Approval
A Google Cloud feature that requires explicit approval from you before Google personnel can access your Google Cloud data or resources to assist with support or maintenance.
- Provides an audit trail of all access approvals/denials.
- You can approve or deny access requests.
- Primarily for Google's access to your data, not your users' access to your data.
Memory trick: Approval Ensures Every Entry Allowed.