Cloud Digital Leader Trust and security with Google Cloud Practice Question
A company's security team wants to detect and remediate public exposure of Cloud SQL instances. Which service should they use?
⚠ Common exam trap
It's easy for candidates to confuse services that enforce security (like VPC Service Controls or Cloud Armor) with services that detect and alert on misconfigurations, leading them to pick a tool that blocks or filters traffic rather than one that provides visibility and detection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security Command Center
Security Command Center (SCC) is the correct service because it provides centralized visibility and monitoring of Google Cloud resources, including the ability to detect and alert on public exposure of Cloud SQL instances. SCC's built-in vulnerability and threat detection findings, such as 'Public SQL instance,' directly identify misconfigured Cloud SQL instances that are accessible from the internet, enabling the security team to remediate the exposure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cloud Armor
Why it's wrong here
Cloud Armor is a distributed denial-of-service protection and web application firewall that inspects incoming HTTP/S traffic against user-defined rules. It does not continuously scan the resource inventory for misconfigurations such as a Cloud SQL instance with a public IP address. Thus, while it can mitigate attacks on exposed services, it cannot detect that the exposure exists in the first place.
- ✓
Security Command Center
Why this is correct
Security Command Center is Google Cloud's security and risk management platform that continuously monitors resources for vulnerabilities, threats, and misconfigurations. It includes built-in detectors that flag publicly exposed Cloud SQL instances by checking assigned IP addresses and IAM policies against best practices. This makes it the correct choice for identifying and remediating the public exposure described in the scenario.
- ✗
Cloud Data Loss Prevention (DLP)
Why it's wrong here
Cloud Data Loss Prevention is designed to inspect content for sensitive data types such as credit card numbers or personally identifiable information, and then apply redaction or tokenization. It operates on data, not on cloud resource configurations, so it cannot determine whether a Cloud SQL instance's network settings expose it to the public internet. Its purpose is protecting data at rest or in transit, not auditing the infrastructure that stores that data.
- ✗
VPC Service Controls
Why it's wrong here
VPC Service Controls establishes security perimeters around Google Cloud services to prevent data exfiltration by denying access from outside the perimeter. It is a preventive control that enforces boundaries, but it does not perform detection or alerting on existing resource exposure. Therefore, it cannot identify that a Cloud SQL instance has been publicly assigned an IP address; it only blocks traffic if configured with a perimeter.
Go deeper
Related to this question
Learn chapter
Cloud Digital Transformation
Key term
Alert
An alert is a notification that something unusual or potentially harmful has happened in a computer system or network.
Key term
Security Command Center
Security Command Center is a centralized cloud security management platform that helps organizations detect, investigate, and respond to threats across their cloud infrastructure.
About these practice questions
Courseiva writes every GCDL question from scratch — 829 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.