Soru

Zorluk: OrtaSecurity Logging, Audit Logs, and Security Command Center

An enterprise security team requires security analysts to inspect Security Command Center (SCC) threat findings and view centralized Data Access audit logs in Cloud Logging across an entire Google Cloud organization. The analysts must not be permitted to read underlying customer data stored in Cloud Storage buckets or alter security configuration policies. Furthermore, the architecture must establish boundaries to prevent authorized analysts from copying log data to external Google Cloud projects outside the organization's administrative domain. Which architectural approach satisfies these security and compliance requirements?

  1. Grant security analysts the Security Center Finder and Logs Viewer predefined roles at the organization level, and enforce VPC Service Controls perimeters around the resources containing audit logs.Cevap
  2. B
    Grant security analysts the primitive Viewer role at the organization level to provide visibility across Security Command Center findings, Cloud Logging sinks, and underlying storage buckets.
  3. C
    Grant security analysts the Security Center Finder and Logs Viewer predefined roles at the organization level, relying strictly on IAM policy restrictions to prevent authorized analysts from copying log data into external Cloud Storage buckets.
  4. D
    Grant security analysts the Service Account Admin role alongside the Security Center Editor role at the organization level so they can manage identities and log export sinks directly.

Cevap

Grant security analysts the predefined roles Security Center Finder and Logs Viewer at the organization level, while establishing VPC Service Controls perimeter boundaries around log storage resources to restrict data movement.
Combining fine-grained predefined roles (Security Center Finder and Logs Viewer) ensures least-privilege access by permitting threat finding inspection and log auditing while restricting access to underlying Cloud Storage object content and security configurations. Coupling these roles with VPC Service Controls creates a security perimeter that prevents authorized users from transferring log data to resources in external, unapproved Google Cloud projects.

Adım Adım Çözüm

1
Identify least-privilege IAM roles for viewing Security Command Center findings and audit logs without granting content access or policy modification rights.
Selected Security Center Finder (roles/securitycenter.finder) for viewing findings and Logs Viewer (roles/logging.viewer) for auditing logs.
Predefined roles restrict permissions to necessary read-only operational telemetry without granting data payload access in Cloud Storage.
2
Evaluate data exfiltration protection requirements for authorized identities.
Determined that IAM policies alone do not block authorized users from exfiltrating data to external Google Cloud projects.
VPC Service Controls perimeters define network-level security boundaries that prevent copying or transferring data outside designated organization projects.

Anahtar Kavram

Combining Least-Privilege IAM Roles with VPC Service Controls for Log Security
Bu soruyu puanla