Soru

Zorluk: OrtaSecurity Logging, Audit Logs, and Security Command Center

A logistics enterprise needs to automatically identify misconfigurations���such as open network firewall rules and publicly accessible Cloud Storage buckets—across all projects in its Google Cloud organization. Furthermore, the compliance team must view administrative audit logs and security findings while strictly adhering to the principle of least privilege. Which architecture and access management strategy satisfies these security requirements?

  1. Enable Security Command Center Security Health Analytics at the organization level, and grant the compliance team the Security Center Findings Viewer (roles/securitycenter.findingsViewer) and Logs Viewer (roles/logging.viewer) predefined roles.Cevap
  2. B
    Enable Security Command Center across individual projects and grant the compliance team the primitive Owner role (roles/owner) across all projects so they have full visibility into security findings and audit logs.
  3. C
    Configure Cloud Audit Logs with custom filters and rely exclusively on IAM read permissions to ensure audit log contents cannot be exfiltrated to external Cloud Storage buckets outside the organization.
  4. D
    Create a service account for automated security monitoring and assign it the Service Account Admin role (roles/iam.serviceAccountAdmin) to grant it sufficient permissions to read Security Command Center assets.

Cevap

The correct strategy is to enable Security Command Center Security Health Analytics at the organization level and grant the compliance team the Security Center Findings Viewer and Logs Viewer roles.
Enabling Security Command Center Security Health Analytics at the organization level provides automated detection of vulnerabilities such as publicly exposed buckets and open firewalls across all project environments. Combining the Security Center Findings Viewer role with the Logs Viewer role provides the compliance team with precise, read-only access to audit logs and security findings in alignment with least-privilege security principles.

Adım Adım Çözüm

1
Identify the automated scanning mechanism for infrastructure misconfigurations
Security Command Center Security Health Analytics scans GCP organization resources for vulnerabilities and misconfigurations like public storage buckets or open firewalls.
Centralizing Security Health Analytics at the organization level ensures uniform coverage across all current and future projects.
2
Select least-privilege IAM roles for reviewing findings and audit logs
The Security Center Findings Viewer role (roles/securitycenter.findingsViewer) permits viewing Security Command Center findings, and Logs Viewer (roles/logging.viewer) allows inspecting audit logs.
Predefined security roles satisfy auditor requirements without granting write or administrative privileges.

Anahtar Kavram

Centralized Security Logging and Security Command Center Governance
Bu soruyu puanla