Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise is deploying automated AI agents built on the Gemini Enterprise Agent Platform. The security operations team needs to establish continuous auditing and threat detection to identify suspicious behavior by agent service account identities.
Specifically, the security team must detect:
Which solution should the security engineer implement to satisfy these requirements?
Security Command Center (SCC) Event Threat Detection (ETD) provides built-in control-plane threat detectors tailored specifically for AI agents running on the Gemini Enterprise Agent Platform and Agent Runtime. ETD continuously analyzes Cloud Audit Logs (including Admin Activity and IAM Data Access audit logs) and Agent Engine Logs to identify anomalous, malicious, or policy-violating behaviors in near real time.
AGENT_ENGINE_IAM_ANOMALOUS_BEHAVIOR_SERVICE_ACCOUNT_GETS_OWN_IAM_POLICY. This detector evaluates IAM Data Access audit logs (DATA_READ permissions) to identify when an identity associated with an AI agent queries and inspects the IAM policies bound to its own service account.AGENT_ENGINE_UNAUTHORIZED_SERVICE_ACCOUNT_API_CALL, which inspects Admin Activity audit logs to flag instances where an AI agent's service account invokes unauthorized methods against outside Google Cloud projects.Leveraging native Event Threat Detection eliminates the operational overhead of creating and maintaining custom log parsing rules while delivering purpose-built behavioral analysis designed by Google Cloud for enterprise agentic workloads.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.