Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise enforces strict Infrastructure-as-Code (IaC) baselines across its entire Google Cloud organization. To minimize the window of exposure caused by out-of-band modifications, the security engineering team must design a continuous drift detection and automated remediation pipeline.
The solution must satisfy the following architectural requirements:
Which architecture should the security team deploy?
Deploy a Cloud Composer environment that schedules hourly DAGs to execute Terraform plan across all projects, writes drift records to BigQuery, and triggers Cloud Workflows to re-apply Terraform states.
Configure Security Command Center (SCC) continuous exports and Cloud Asset Inventory real-time feeds to stream findings and resource state changes to Pub/Sub topics, and trigger Cloud Functions via Pub/Sub subscriptions to execute programmatic remediations.
Configure Cloud Audit Logs aggregated log sinks at the organization root routed directly to Cloud Functions HTTP endpoints using Webhooks to parse IAM mutations and rollback drift.
Enable Compliance Manager in Security Command Center to automatically mute duplicate Security Health Analytics detectors and directly execute automated infrastructure rollbacks natively within the SCC dashboard.
Deploy a Cloud Composer environment that schedules hourly DAGs to execute Terraform plan across all projects, writes drift records to BigQuery, and triggers Cloud Workflows to re-apply Terraform states.
Configure Security Command Center (SCC) continuous exports and Cloud Asset Inventory real-time feeds to stream findings and resource state changes to Pub/Sub topics, and trigger Cloud Functions via Pub/Sub subscriptions to execute programmatic remediations.
This architecture combines Security Command Center (SCC) Continuous Exports, Cloud Asset Inventory (CAI) real-time feeds, Cloud Pub/Sub, and Cloud Functions to provide an enterprise-grade, event-driven drift detection and remediation pipeline across a Google Cloud organization.
Leveraging native Pub/Sub streaming with Cloud Functions creates an asynchronous, event-driven security workflow that operates in sub-second response times without the compute costs, latency, or API quota consumption of continuous batch scanning.
Configure Cloud Audit Logs aggregated log sinks at the organization root routed directly to Cloud Functions HTTP endpoints using Webhooks to parse IAM mutations and rollback drift.
Enable Compliance Manager in Security Command Center to automatically mute duplicate Security Health Analytics detectors and directly execute automated infrastructure rollbacks natively within the SCC dashboard.