Identify Misconfigurations & Compliance Violations in Google Cloud

Security Command Center / Security Posture Management
Answer Correct answer: B — Use Security Health Analytics detectors in Security Command Center Premium to scan for common misconfigurations and compliance violations across your organization.

Your organization's use of the Google Cloud has grown substantially and there are many different groups using different cloud resources independently. You must identify common misconfigurations and compliance violations across the organization and track findings for remedial action in a dashboard. What should you do?

  1. Create a filter set in Cloud Asset Inventory to identify service accounts with high privileges and IAM principals with Gmail domains.
  2. Scan and alert vulnerabilities and misconfigurations by using Secure Health Analytics detectors in Security Command Center Premium. Correct Answer
  3. Set up filters on Cloud Audit Logs to flag log entries for specific, risky API calls, and display the calls in a Cloud Log Analytics dashboard.
  4. Alert and track emerging attacks detected in your environment by using Event Threat Detection detectors.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests knowledge of SCC Premium's built-in posture management tool versus log-based monitoring or threat detection services.

Security Health Analytics in SCC Premium automatically scans cloud environments for common misconfigurations and compliance violations, providing a centralized dashboard to track and remediate findings.

Candidates often confuse Security Health Analytics with Event Threat Detection, incorrectly choosing the latter because it handles attacks rather than static configuration flaws.

Community Discussion (3 comments)

Pime13 👍 1 Selected: B
https://cloud.google.com/security-command-center/docs/concepts-security-health-analytics Security Health Analytics is a managed service of Security Command Center that scans your cloud environments for common misconfigurations that might expose you to attack. Security Health Analytics is automatically enabled when you activate Security Command Center
MoAk 👍 1 Selected: B
https://cloud.google.com/security-command-center/docs/concepts-security-health-analytics
yokoyan 👍 2 Selected: B
I think it's B.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Security Health Analytics is a core feature of Security Command Center Premium designed specifically to continuously scan workloads for common misconfigurations and compliance violations. It evaluates resources against industry best practices and regulatory benchmarks, automatically generating findings that can be tracked and prioritized in a unified dashboard. This directly satisfies the requirement to identify cross-group misconfigurations and manage remedial actions efficiently.

Why the Other Options Are Wrong

Cloud Asset Inventory focuses on resource metadata and discovery, not proactive security scanning or compliance tracking. Cloud Audit Logs record API activity; while filtering them reveals who made risky calls, it does not detect underlying infrastructure misconfigurations. Event Threat Detection relies on threat intelligence to flag active exploitation attempts, making it unsuitable for routine compliance and configuration audits.

Community Comment Notes

Learners consistently validate this choice by referencing official documentation that defines the service as an automated scanner for cloud misconfigurations. Several users noted that enabling SCC automatically activates these detectors, reinforcing why option B is the standard operational approach. As user Pime13 noted, the tool 'scans your cloud environments for common misconfigurations', which perfectly aligns with the exam scenario.

Official Reference

Exam Strategy

Focus on mapping exam keywords to specific GCP security products: "misconfigurations and compliance" points directly to Security Health Analytics, while "emerging attacks" points to Event Threat Detection and "resource discovery" points to Cloud Asset Inventory. Memorizing these keyword-to-product mappings will save time during the exam.

Frequently Asked Questions

Why isn't Event Threat Detection the right choice?

ETD focuses on detecting active exploits and emerging attacks using threat intelligence, not on auditing static misconfigurations or compliance baselines.

Does Security Health Analytics require manual setup?

No, it is automatically enabled when you activate Security Command Center and runs continuous scans without manual detector configuration.

Related Analysis

← Back to PCSE Study Guide