Your organization operates in a highly regulated industry and uses multiple Google Cloud services. You need to identify potential risks to regulatory compliance. Which situation introduces the greatest risk?
A.
The security team mandates the use of customer-managed encryption keys (CMEK) for all data classified as sensitive.
B.
Sensitive data is stored in a Cloud Storage bucket with the uniform bucket-level access setting enabled.
C.
The audit team needs access to Cloud Audit Logs related to managed services like BigQuery.
D.
Principals have broad IAM roles allowing the creation and management of Compute Engine VMs without a pre-defined hardening process.
D - Lack of Control: This situation grants individuals broad permissions to create and manage VMs without ensuring that they adhere to necessary security standards. This lack of control can lead to the creation of vulnerable or non-compliant systems.
Regulatory Implications: Depending on your industry and specific regulations, having unhardened systems can expose your organization to significant risks, such as data breaches, unauthorized access, or non-compliance with security requirements.
upvoted 3 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
json4u
1 month, 1 week agoabdelrahman89
1 month, 2 weeks ago