Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise organization integrates its automated user lifecycle management system with Google Cloud. The security team needs to establish continuous security and access governance monitoring to identify lifecycle anomalies, such as dormant accounts being granted sensitive roles or unmanaged external identities receiving project-level privileges. Additionally, they require automated remediation to remove unauthorized permissions and disable compromised service accounts when these anomalies occur.
Which solution should the security team implement to satisfy these detection and remediation requirements?
Configure Cloud Logging log-based metrics with Cloud Monitoring alert policies, and route webhook notifications to Cloud Functions to delete IAM policy bindings from Cloud Identity.
Enable Security Command Center Event Threat Detection using Cloud Audit Logs to identify anomalous IAM grants, and trigger Google Security Operations (SOAR) playbooks to automatically remediate unauthorized bindings and disable affected accounts.
Export Cloud Asset Inventory resource feeds to BigQuery, schedule recurring SQL queries to locate dormant identities, and invoke Cloud Run jobs to revoke excess IAM permissions.
Enable IAM Recommender with automated unattended rollout policies in Policy Intelligence to immediately apply role recommendations and remove unused permissions.
Configure Cloud Logging log-based metrics with Cloud Monitoring alert policies, and route webhook notifications to Cloud Functions to delete IAM policy bindings from Cloud Identity.
Enable Security Command Center Event Threat Detection using Cloud Audit Logs to identify anomalous IAM grants, and trigger Google Security Operations (SOAR) playbooks to automatically remediate unauthorized bindings and disable affected accounts.
Security Command Center (SCC) with Event Threat Detection (ETD) and Google Security Operations (SecOps) provides integrated threat detection, identity governance, and automated incident response across the Google Cloud environment. Event Threat Detection analyzes IAM Admin Activity audit logs and system event logs in near-real-time to detect anomalous changes, unauthorized privilege escalations, and persistence mechanisms across the identity lifecycle.
Persistence: Unmanaged Account Granted Sensitive Role, Privilege Escalation: Dormant Service Account Granted Sensitive Role, and Persistence: IAM Anomalous Grant.roles/chronicle.soarServiceAgent), playbooks can automatically invoke actions like updating IAM policies, revoking role bindings, and executing iam.serviceAccounts.disable.This architecture establishes a closed-loop security operations workflow natively inside Google Cloud, ensuring zero-latency threat detection for identity lifecycle policy deviations paired with deterministic, auditable SOAR remediation.
Export Cloud Asset Inventory resource feeds to BigQuery, schedule recurring SQL queries to locate dormant identities, and invoke Cloud Run jobs to revoke excess IAM permissions.
Enable IAM Recommender with automated unattended rollout policies in Policy Intelligence to immediately apply role recommendations and remove unused permissions.