Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
A security operations team uses Google Cloud Security Command Center (SCC) across an enterprise organization to monitor misconfigurations, vulnerabilities, and runtime threats identified by integrated services such as Security Health Analytics and Virtual Machine Threat Detection.
The team wants to enhance finding triage and response planning by contextualizing detected threats with data risk. Additionally, they need SCC's attack path simulation feature to automatically prioritize exposed resources according to the calculated sensitivity of the data they store.
Which configuration should the security team implement to meet these requirements?
Enable Virtual Machine Threat Detection memory analysis to scan compute instances and stream raw memory dumps to Google Security Operations for data classification.
Create custom Security Health Analytics rules that inspect storage object payloads directly and generate findings when unencrypted sensitive data is detected.
Configure an Event Threat Detection finding export that triggers a Cloud Function to execute ad-hoc Cloud DLP inspection jobs for any resource referenced in an alert.
Configure Sensitive Data Protection discovery scan configurations with the appropriate inspection templates and enable the action to publish data profiles to Security Command Center.
Sensitive Data Protection (SDP) discovery and profiling services automatically scan, classify, and generate risk profiles for data stored across supported cloud storage assets. By configuring discovery scan configurations to Publish to Security Command Center, generated data profiles and sensitivity metrics are continuously exported directly into the Security Command Center finding and asset database.
Enabling direct data profile publishing from Sensitive Data Protection is the standard, native integration method in Google Cloud for linking data sensitivity metrics to Security Command Center's asset inventory and attack path simulation engine without requiring custom event-forwarding pipelines.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Still curious? Scout, our AI tutor, can explain this concept further and answer your follow-up questions.