nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #341

Your organization strives to be a market leader in software innovation. You provided a large number of Google Cloud environments so developers can test the integration of Gemini in Vertex AI into…

The correct answer is A. Apply organization policy constraints. Detect and monitor drifts by using Security Health Analytics. D. Apply a predefined AI-recommended security posture template for Gemini in Vertex AI in Security. With only 5 security engineers overseeing 200 developers across many Google Cloud environments, automation and scalable tooling are essential. Option A is correct because organization policy constraints enforce guardrails (e.g., restricting regions, disabling public IPs) across…

Submitted by lukas.cz· Apr 18, 2026Ensuring compliance

Question

Your organization strives to be a market leader in software innovation. You provided a large number of Google Cloud environments so developers can test the integration of Gemini in Vertex AI into their existing applications or create new projects. Your organization has 200 developers and a five-person security team. You must prevent and detect proper security policies across the Google Cloud environments. What should you do? (Choose two.)

Options

  • AApply organization policy constraints. Detect and monitor drifts by using Security Health Analytics.
  • BPublish internal policies and clear guidelines to securely develop applications.
  • CUse Cloud Logging to create log filters to detect misconfigurations. Trigger Cloud Run functions to
  • DApply a predefined AI-recommended security posture template for Gemini in Vertex AI in Security
  • EImplement the least privileged access Identity and Access Management roles to prevent

How the community answered

(36 responses)
  • A
    75% (27)
  • B
    8% (3)
  • C
    14% (5)
  • E
    3% (1)

Explanation

With only 5 security engineers overseeing 200 developers across many Google Cloud environments, automation and scalable tooling are essential. Option A is correct because organization policy constraints enforce guardrails (e.g., restricting regions, disabling public IPs) across all projects automatically, while Security Health Analytics continuously monitors for misconfigurations and policy drift without manual effort. Option D is correct because Security Command Center provides a predefined AI-recommended security posture template specifically designed for Gemini in Vertex AI workloads, giving the security team a curated baseline that detects and remediates AI-specific risks out of the box. Option B (publishing internal policies) is helpful culturally but does not technically prevent or detect violations. Option C (Cloud Logging + Cloud Run) could work but requires significant custom development. Option E (least privilege IAM) is best practice but alone does not address detection or broader policy enforcement at scale.

Topics

#Organization Policy#Security Command Center#Policy Enforcement#Misconfiguration Detection

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice