Hard1 markMultiple Choice
Domain 3: Designing for Security and ComplianceSecurity Command CenterSecurityArtifact Registry

GCP PCA · Question 45 · Domain 3: Designing for Security and Compliance

You are configuring Security Command Center (SCC) Premium for your organization. The CISO wants to automatically detect if any Cloud Storage buckets are made public, and wants to identify vulnerabilities in container images stored in Artifact Registry. Which TWO SCC built-in services should you ensure are enabled? (Select TWO)

Answer options:

A.

Security Health Analytics

B.

Event Threat Detection

C.

Container Threat Detection

D.

Web Security Scanner

E.

VPC Service Controls

How to approach this question

Identify the SCC module that checks for misconfigurations (Health Analytics) and the one that checks containers.

Full Answer

Security Command Center Premium includes several built-in services. Security Health Analytics (Option A) continuously monitors resource configurations against best practices, immediately flagging public buckets. Container Threat Detection / Container Analysis (Option C) scans images in Artifact Registry for known CVEs (vulnerabilities).

Common mistakes

Choosing Event Threat Detection (B). ETD looks at logs for active attacks, not static misconfigurations like a public bucket.

Practice the full GCP Professional Cloud Architect Practice Exam 4

50 questions · hints · full answers · grading

More questions from this exam