PCSE Practice Question: Managing Operations in a Cloud Solution Environment
A financial services company uses Security Command Center (SCC) Premium tier to monitor its GCP environment. The security team wants to automatically respond to high-severity threat findings, such as 'Cryptomining' from Event Threat Detection. The response should include isolating the affected VM by removing its external IP and applying a firewall rule to block egress traffic. Which two steps should the team implement? (Choose two.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy a Cloud Function that listens on the Pub/Sub topic and uses Compute Engine API to modify the VM's network tags and update firewall rules
SCC can be integrated with Pub/Sub to send real-time notifications for findings, and Cloud Functions can execute automated remediation actions like modifying VM network tags or applying firewall rules.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Deploy a Cloud Function that listens on the Pub/Sub topic and uses Compute Engine API to modify the VM's network tags and update firewall rules
Why this is correct
Cloud Functions can automate remediation based on SCC findings.
- ✗
Create a Security Health Analytics scan to detect similar threats
Why it's wrong here
Security Health Analytics scans for misconfigurations, not for responding to existing threats.
- ✗
Set up a log sink to export Admin Activity logs to BigQuery
Why it's wrong here
This is for analysis, not real-time automated response.
- ✗
Enable VPC Flow Logs for the affected VM's subnet
Why it's wrong here
VPC Flow Logs provide network monitoring but do not trigger automated responses.
- ✓
Create a Pub/Sub topic and subscribe SCC findings to it using a notification config
Why this is correct
SCC can stream findings to Pub/Sub for real-time processing.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
One of 960 original PCSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCSE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCSE exam.