nerdexam
Google

PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #89

Your company requires PCI DSS v4.0 compliance for its cardholder data environment (CDE) in Google Cloud. You use a Security Command Center (SCC) security posture deployment based on the PCI DSS v4.0 t

The correct answer is B. Reconfigure the network interface settings for the VM to explicitly remove the assigned external. To immediately remediate the compliance drift, you should reconfigure the network interface of the VM to remove the external IP address. This directly addresses the issue identified by the SCC PCI DSS v4.0 posture finding, ensuring the VM no longer violates the standard, rather t

Compliance Remediation

Question

Your company requires PCI DSS v4.0 compliance for its cardholder data environment (CDE) in Google Cloud. You use a Security Command Center (SCC) security posture deployment based on the PCI DSS v4.0 template to monitor for configuration drift. This posture generates a finding indicating that a Compute Engine VM within the CDE scope has been configured with an external IP address. You need to take an immediate action to remediate the compliance drift identified by this specific SCC posture finding. What should you do?

Options

  • AEnable and enforce the constraints/compute.vmExternalIpAccess organization policy constraint at
  • BReconfigure the network interface settings for the VM to explicitly remove the assigned external
  • CRemove the CDE-specific tag from the VM to exclude the tag from this particular PCI DSS
  • DNavigate to the underlying Security Health Analytics (SHA) finding for PUBLIC_IP_ADDRESS on

How the community answered

(46 responses)
  • A
    2% (1)
  • B
    85% (39)
  • C
    4% (2)
  • D
    9% (4)

Explanation

To immediately remediate the compliance drift, you should reconfigure the network interface of the VM to remove the external IP address. This directly addresses the issue identified by the SCC PCI DSS v4.0 posture finding, ensuring the VM no longer violates the standard, rather than just suppressing or marking the finding.

Topics

#PCI DSS compliance#Security Command Center posture#external IP remediation#Compute Engine

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER Practice