Medium1 markMultiple Choice
Subtask 3.2: Compliance DesignSecurity Command CenterSOC 2ComplianceSecurity Health Analytics

GCP PCA · Question 41 · Compliance Design

Your organization is preparing for a SOC 2 audit. The auditors require proof that you are continuously monitoring your GCP environment for misconfigurations (e.g., public Cloud Storage buckets, open firewall rules) and that you have a centralized dashboard for security alerts. Which TWO GCP services should you utilize? (Select TWO)

Answer options:

A.

Cloud Monitoring

B.

Cloud Audit Logs

C.

Security Command Center (SCC)

D.

VPC Service Controls

E.

Security Health Analytics

How to approach this question

Identify the GCP centralized security dashboard and its built-in scanner for misconfigurations.

Full Answer

C,E
Security Command Center (SCC) is Google Cloud's native security and risk management platform, providing a centralized dashboard for all security alerts. Within SCC, Security Health Analytics automatically runs continuous scans against your GCP infrastructure to detect misconfigurations (like publicly accessible buckets, open firewall ports, or missing MFA) and maps them to compliance standards like SOC 2.

Common mistakes

Choosing Cloud Monitoring (Option A). Monitoring is for operational health (SRE), while SCC is for security posture.

Practice the full GCP Professional Cloud Architect Practice Exam 7

50 questions · hints · full answers · grading

More questions from this exam