Google Professional Cloud Security Engineer Exam - Topic 2 Question 53 Discussion
You need to enforce a security policy in your Google Cloud organization that prevents users from exposing objects in their buckets externally. There are currently no buckets in your organization. Which solution should you implement proactively to achieve this goal with the least operational overhead?
B) Enable the constraints/storage.publicAccessPrevention constraint at the organization level.
A) Create an hourly cron job to run a Cloud Function that finds public buckets and makes them private.
C) Enable the constraints/storage.uniformBucketLevelAccess constraint at the organization level.
D) Create a VPC Service Controls perimeter that protects the storage.googleapis.com service in your projects that contains buckets. Add any new project that contains a bucket to the perimeter.
Mitsue
10 months agoLaila
10 months agoLuisa
10 months agoDaniel
11 months agoCherri
11 months agoCurtis
11 months agoShenika
11 months agoTarra
11 months agoAmira
11 months agoSarah
11 months agoKate
11 months agoGail
11 months ago