nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #236

Your organization wants to be continuously evaluated against CIS Google Cloud Computing Foundations Benchmark v1.3.0 (CIS Google Cloud Foundation 1.3). Some of the controls are irrelevant to your…

The correct answer is B. Activate Security Command Center (SCC) Premium. Create a rule to mute the security findings in. Security Command Center (SCC) Premium natively supports the CIS Google Cloud Computing Foundations Benchmark as a built-in compliance standard. To exclude irrelevant controls from evaluation without losing the automated continuous monitoring, you activate SCC Premium and use…

Submitted by ravi_2018· Apr 18, 2026Ensuring compliance

Question

Your organization wants to be continuously evaluated against CIS Google Cloud Computing Foundations Benchmark v1.3.0 (CIS Google Cloud Foundation 1.3). Some of the controls are irrelevant to your organization and must be disregarded in evaluation. You need to create an automated system or process to ensure that only the relevant controls are evaluated. What should you do?

Options

  • AMark all security findings that are irrelevant with a tag and a value that indicates a security
  • BActivate Security Command Center (SCC) Premium. Create a rule to mute the security findings in
  • CDownload all findings from Security Command Center (SCC) to a CSV file. Mark the findings that
  • DAsk an external audit company to provide independent reports including needed CIS

How the community answered

(37 responses)
  • A
    5% (2)
  • B
    78% (29)
  • C
    3% (1)
  • D
    14% (5)

Explanation

Security Command Center (SCC) Premium natively supports the CIS Google Cloud Computing Foundations Benchmark as a built-in compliance standard. To exclude irrelevant controls from evaluation without losing the automated continuous monitoring, you activate SCC Premium and use its 'mute rules' feature. Mute rules allow you to define criteria (by finding category, resource type, etc.) so that matching findings are automatically muted - excluded from active dashboards and reports - while the evaluation itself still runs. This gives you an automated, auditable system where only relevant findings surface. Option A (adding tags) is manual and does not prevent findings from appearing. Option C (CSV export and manual marking) is manual and not automated. Option D (external auditor) does not create an automated system and is not a Google Cloud service.

Topics

#Security Command Center#CIS Benchmarks#Compliance Management#Muting Rules

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice