nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #316

Your organization operates in a highly regulated industry and uses multiple Google Cloud services. You need to identify potential risks to regulatory compliance. Which situation introduces the…

The correct answer is D. Principals have broad IAM roles allowing the creation and management of Compute Engine VMs. Lack of Control: This situation grants individuals broad permissions to create and manage VMs without ensuring that they adhere to necessary security standards. This lack of control can lead to the creation of vulnerable or non-compliant systems. Regulatory Implications…

Submitted by manish99· Apr 18, 2026Configuring access within a cloud solution environment

Question

Your organization operates in a highly regulated industry and uses multiple Google Cloud services. You need to identify potential risks to regulatory compliance. Which situation introduces the greatest risk?

Options

  • AThe security team mandates the use of customer-managed encryption keys (CMEK) for all data
  • BSensitive data is stored in a Cloud Storage bucket with the uniform bucket-level access setting
  • CThe audit team needs access to Cloud Audit Logs related to managed services like BigQuery.
  • DPrincipals have broad IAM roles allowing the creation and management of Compute Engine VMs

How the community answered

(37 responses)
  • A
    8% (3)
  • B
    11% (4)
  • C
    22% (8)
  • D
    59% (22)

Explanation

Lack of Control: This situation grants individuals broad permissions to create and manage VMs without ensuring that they adhere to necessary security standards. This lack of control can lead to the creation of vulnerable or non-compliant systems. Regulatory Implications: Depending on your industry and specific regulations, having unhardened systems can expose your organization to significant risks, such as data breaches, unauthorized access, or non-compliance with security requirements.

Topics

#IAM#Least Privilege#Risk Management#Regulatory Compliance

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice