PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #316
Your organization operates in a highly regulated industry and uses multiple Google Cloud services. You need to identify potential risks to regulatory compliance. Which situation introduces the…
The correct answer is D. Principals have broad IAM roles allowing the creation and management of Compute Engine VMs. Lack of Control: This situation grants individuals broad permissions to create and manage VMs without ensuring that they adhere to necessary security standards. This lack of control can lead to the creation of vulnerable or non-compliant systems. Regulatory Implications…
Question
Options
- AThe security team mandates the use of customer-managed encryption keys (CMEK) for all data
- BSensitive data is stored in a Cloud Storage bucket with the uniform bucket-level access setting
- CThe audit team needs access to Cloud Audit Logs related to managed services like BigQuery.
- DPrincipals have broad IAM roles allowing the creation and management of Compute Engine VMs
How the community answered
(37 responses)- A8% (3)
- B11% (4)
- C22% (8)
- D59% (22)
Explanation
Lack of Control: This situation grants individuals broad permissions to create and manage VMs without ensuring that they adhere to necessary security standards. This lack of control can lead to the creation of vulnerable or non-compliant systems. Regulatory Implications: Depending on your industry and specific regulations, having unhardened systems can expose your organization to significant risks, such as data breaches, unauthorized access, or non-compliance with security requirements.
Topics
Community Discussion
No community discussion yet for this question.