Preventing and Detecting Security Policy Drift in GCP Environments

Cloud Security Command Center & Organization Policies

Your organization strives to be a market leader in software innovation. You provided a large number of Google Cloud environments so developers can test the integration of Gemini in Vertex AI into their existing applications or create new projects. Your organization has 200 developers and a five-person security team. You must prevent and detect proper security policies across the Google Cloud environments. What should you do? (Choose two.)

  1. Apply organization policy constraints. Detect and monitor drifts by using Security Health Analytics. Source Reference Answer
  2. Publish internal policies and clear guidelines to securely develop applications.
  3. Use Cloud Logging to create log filters to detect misconfigurations. Trigger Cloud Run functions to remediate misconfigurations.
  4. Apply a predefined AI-recommended security posture template for Gemini in Vertex AI in Security Command Center Enterprise or Premium tiers. Source Reference Answer
  5. Implement the least privileged access Identity and Access Management roles to prevent misconfigurations.

Community Votes

AD
80%
AE
20%

80% of anonymous learners picked answer AD. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests scalable policy enforcement and drift detection, where candidates often mistakenly choose manual logging/remediation or generic IAM instead of native posture management tools.

Learn how to prevent and detect security policy drift across large-scale Google Cloud environments using Organization Policy constraints and Security Command Center posture templates. This page clarifies why combining policy enforcement with AI-specific security templates is the optimal PCSE solution.

Option E is frequently selected because least-privilege IAM is a fundamental security principle, but it focuses on identity access rather than environment-wide policy compliance and configuration drift detection required by the prompt.

Community Discussion (4 comments)

YourFriendlyNeighborhoodSpider 👍 1 Selected: AD
I agree with nah99, A and D seems reasonable given Vertex AI is mentioned.
nah99 👍 2 Selected: AD
Specifically mentions gemini/vertex, so definitely D. https://cloud.google.com/security-command-center/docs/security-posture-essentials-secure-ai-template A & E are both good, but the requirement is prevent and detect, which better lines to A.
BPzen 👍 1 Selected: AE
A. Apply organization policy constraints. Detect and monitor drifts by using Security Health Analytics. Organization Policies: Enforcing organization policies (e.g., constraints on resource locations, API access, or service usage) helps standardize security practices across all environments. Developers can create and test environments without bypassing critical security controls. Security Health Analytics (SHA): SHA, available in Security Command Center Premium, detects and alerts on violations of security best practices and misconfigurations, such as overly permissive roles or public resource exposure. E. Implement the least privileged access Identity and Access Management roles to prevent misconfigurations. Least Privileged Access: Assigning IAM roles based on the principle of least privilege prevents users from making changes outside their scope of work, reducing misconfiguration risks.
abdelrahman89 👍 1 Selected: AD
Answer A D

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option A leverages Organization Policy constraints to proactively prevent non-compliant resource configurations across all 200 developer projects, while Security Health Analytics continuously monitors for drift. Option D applies a workload-specific Security Posture Management template from Security Command Center tailored for AI services like Vertex AI and Gemini, ensuring industry-standard controls are enforced and violations are detected automatically. Together, these native GCP capabilities provide a scalable, automated prevent-and-detect framework perfectly suited for a lean five-person security team managing high-velocity development.

Why the Other Options Are Wrong

Option B relies solely on documentation and lacks technical enforcement or automated detection mechanisms. Option C proposes a custom Cloud Logging and Cloud Run remediation pipeline that introduces unnecessary complexity and operational overhead compared to out-of-the-box posture management. Option E enforces identity-level access restrictions but does not address infrastructure misconfigurations, policy compliance, or continuous security monitoring across cloud environments.

Community Comment Notes

Community consensus strongly favors the AD combination, with multiple learners noting that the explicit mention of Gemini and Vertex AI directly points toward the AI-specific SCC template. Several users highlighted that while IAM least privilege is critical, it does not satisfy the dual requirement of preventing configuration drift and detecting policy violations at scale. As one contributor observed, the native posture management features align precisely with the exam’s focus on automated security governance.

Official Reference

Exam Strategy

When a scenario emphasizes scaling security controls across many projects or teams, prioritize native GCP automation tools like Organization Policies and Security Command Center over manual processes or custom scripting. Always match the technology mentioned in the prompt (e.g., AI/ML workloads) to the corresponding specialized posture templates or modules provided by Google.

Frequently Asked Questions

Why isn't least privilege IAM the right choice for detecting drift?

IAM controls identity access but cannot audit infrastructure configurations or enforce policy compliance across environments. You need posture management tools to catch drift.

Does Security Health Analytics replace Security Command Center?

No, SHA feeds findings into SCC, which then correlates them with posture templates and org policies for a unified prevent-and-detect workflow.

Related Analysis

← Back to PCSE Study Guide