Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A financial enterprise hosted on Google Cloud must fulfill stringent data sovereignty and administrative access compliance standards across its resource hierarchy. The organization's security team has established the following requirements:
Which combination of Google Cloud security controls and access governance services meets these requirements?
Create custom Organization Policy constraints using the Resource Manager API, configure Security Command Center alerts for SetIamPolicy calls, and enforce short session reauthentication.
Configure VPC Service Controls with scoped access policies, enforce the domain restriction organization policy, and enable Cloud Audit Logs Data Access logging.
Deploy Policy Controller on GKE, configure Endpoint Verification with device approvals, and enforce certificate-based access levels through Chrome Enterprise Premium.
Enable Access Transparency for audit logging, configure Access Approval across the hierarchy, and use Key Access Justifications with Cloud KMS or Cloud EKM.
Create custom Organization Policy constraints using the Resource Manager API, configure Security Command Center alerts for SetIamPolicy calls, and enforce short session reauthentication.
Configure VPC Service Controls with scoped access policies, enforce the domain restriction organization policy, and enable Cloud Audit Logs Data Access logging.
Deploy Policy Controller on GKE, configure Endpoint Verification with device approvals, and enforce certificate-based access levels through Chrome Enterprise Premium.
Enable Access Transparency for audit logging, configure Access Approval across the hierarchy, and use Key Access Justifications with Cloud KMS or Cloud EKM.
Access Transparency, Access Approval, and Key Access Justifications (KAJ) form Google Cloud's comprehensive administrative access control and data governance framework. Together, they give enterprise customers full visibility, approval authority, and cryptographic oversight over any interactions Google personnel have with customer workloads.
This combination directly satisfies all administrative oversight, explicit manual approval, and cryptographic boundary requirements defined by regulatory frameworks without disrupting normal automated service operations.