Soru

Zorluk: OrtaSecurity Logging, Audit Logs, and Security Command Center

A multinational enterprise wants to implement real-time security threat detection and automated monitoring across its entire Google Cloud resource hierarchy. The security team needs to detect misconfigurations and suspicious activity (such as malware or unauthorized access) at scale without deploying or managing agents on individual virtual machines. Additionally, high-severity findings must trigger immediate notifications to an automated ticketing system. Which native Google Cloud architecture meets these requirements?

  1. Enable Security Command Center Premium at the organization level, utilize Built-in Services such as Event Threat Detection and Security Health Analytics, and configure Continuous Exports to a Cloud Pub/Sub topic for automated alerting.Cevap
  2. B
    Grant the primitive Owner IAM role to the security operations service account across all projects and configure custom Cloud Logging exclusion filters to monitor security audit events manually.
  3. C
    Deploy a custom monitoring agent script to every Compute Engine VM that grants the Service Account Admin role to the instance service account for reading system security logs and forwarding them directly to an external SIEM.
  4. D
    Rely strictly on project-level IAM policy bindings to block unauthorized configuration changes, disabling all Data Access audit logs to prevent data exfiltration across organizational boundaries.

Cevap

Enable Security Command Center Premium at the organization level, utilize Built-in Services such as Event Threat Detection and Security Health Analytics, and configure Continuous Exports to a Cloud Pub/Sub topic for automated alerting.
Enabling Security Command Center (SCC) Premium at the organization tier delivers centralized, agentless threat detection (Event Threat Detection) and misconfiguration scanning (Security Health Analytics). Utilizing SCC's Continuous Export feature automatically streams finding notifications to a Cloud Pub/Sub topic, enabling real-time integration with automated ticketing and remediation pipelines.

Adım Adım Çözüm

1
Identify the threat detection and asset configuration auditing requirements.
Real-time threat detection and security health monitoring are needed across the Google Cloud organization without installing third-party agents on compute instances.
Security Command Center (SCC) Premium provides agentless scanning and log monitoring capabilities (Security Health Analytics and Event Threat Detection) natively integrated with GCP.
2
Determine the mechanism for continuous automated notifications.
Findings generated by SCC Premium need to be streamed to downstream ticketing or alerting systems in real time.
SCC Continuous Export allows automatically publishing security findings directly to a Cloud Pub/Sub topic as they are generated.

Anahtar Kavram

Security Command Center Premium and Automated Finding Exports
Bu soruyu puanla