Professional Cloud Security EngineerConfiguring access within a cloud solution environmentHard

A company requires that all access to highly sensitive data in Cloud Storage buckets must be approved by a designated security team member before access is granted. This approval process should be integrated directly into the Google Cloud IAM workflow. Which Google Cloud feature enables this requirement?

  1. AOrganization Policy Constraints
  2. BData Loss Prevention (DLP)
  3. CAccess Approval
  4. DCloud IAM Conditions
Show answer & explanation

Correct answer: C. Access Approval

Access Approval allows you to require explicit approval for Google personnel to access your Google Cloud resources or data. While not for *your* users, it addresses the core concept of requiring approval *before* access to sensitive data, which is analogous to the scenario described for Google's own access. For *your* users, you would combine IAM, Org Policies, and potentially custom workflows. However, among the given options, Access Approval is the only one *specifically* designed for an approval workflow before access, even if the 'who' is different.

Why the other options are wrong

  • A. Organization Policy Constraints enforce rules across the organization but do not provide an interactive, per-access approval mechanism.
  • B. Data Loss Prevention (DLP) scans and redacts sensitive data, it does not manage access approval workflows.
  • D. Cloud IAM Conditions apply to *when* an existing binding is effective (e.g., time-based, IP-based) but don't implement an explicit 'approval workflow' for every access request.

Google Cloud Access Approval

A Google Cloud feature that requires explicit approval from you before Google personnel can access your Google Cloud data or resources to assist with support or maintenance.

  • Provides an audit trail of all access approvals/denials.
  • You can approve or deny access requests.
  • Primarily for Google's access to your data, not your users' access to your data.

Memory trick: Approval Ensures Every Entry Allowed.

More Configuring access within a cloud solution environment questions