Preventing and Detecting Security Policy Drift in GCP Environments
Your organization strives to be a market leader in software innovation. You provided a large number of Google Cloud environments so developers can test the integration of Gemini in Vertex AI into their existing applications or create new projects. Your organization has 200 developers and a five-person security team. You must prevent and detect proper security policies across the Google Cloud environments. What should you do? (Choose two.)
Community Votes
80% of anonymous learners picked answer AD. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests scalable policy enforcement and drift detection, where candidates often mistakenly choose manual logging/remediation or generic IAM instead of native posture management tools.
Learn how to prevent and detect security policy drift across large-scale Google Cloud environments using Organization Policy constraints and Security Command Center posture templates. This page clarifies why combining policy enforcement with AI-specific security templates is the optimal PCSE solution.
Option E is frequently selected because least-privilege IAM is a fundamental security principle, but it focuses on identity access rather than environment-wide policy compliance and configuration drift detection required by the prompt.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option A leverages Organization Policy constraints to proactively prevent non-compliant resource configurations across all 200 developer projects, while Security Health Analytics continuously monitors for drift. Option D applies a workload-specific Security Posture Management template from Security Command Center tailored for AI services like Vertex AI and Gemini, ensuring industry-standard controls are enforced and violations are detected automatically. Together, these native GCP capabilities provide a scalable, automated prevent-and-detect framework perfectly suited for a lean five-person security team managing high-velocity development.Why the Other Options Are Wrong
Option B relies solely on documentation and lacks technical enforcement or automated detection mechanisms. Option C proposes a custom Cloud Logging and Cloud Run remediation pipeline that introduces unnecessary complexity and operational overhead compared to out-of-the-box posture management. Option E enforces identity-level access restrictions but does not address infrastructure misconfigurations, policy compliance, or continuous security monitoring across cloud environments.Community Comment Notes
Community consensus strongly favors the AD combination, with multiple learners noting that the explicit mention of Gemini and Vertex AI directly points toward the AI-specific SCC template. Several users highlighted that while IAM least privilege is critical, it does not satisfy the dual requirement of preventing configuration drift and detecting policy violations at scale. As one contributor observed, the native posture management features align precisely with the exam’s focus on automated security governance.Official Reference
Exam Strategy
When a scenario emphasizes scaling security controls across many projects or teams, prioritize native GCP automation tools like Organization Policies and Security Command Center over manual processes or custom scripting. Always match the technology mentioned in the prompt (e.g., AI/ML workloads) to the corresponding specialized posture templates or modules provided by Google.
Frequently Asked Questions
Why isn't least privilege IAM the right choice for detecting drift?
IAM controls identity access but cannot audit infrastructure configurations or enforce policy compliance across environments. You need posture management tools to catch drift.
Does Security Health Analytics replace Security Command Center?
No, SHA feeds findings into SCC, which then correlates them with posture templates and org policies for a unified prevent-and-detect workflow.