A security analyst needs visibility into OS vulnerabilities and metadata for a critical Compute Engine instance. How do you provide that access while meeting the policy?
Choose an answer
Tap an option to check your answer.
Correct answer: Install the OS Config agent on the instance and grant the analyst roles/osconfig.vulnerabilityReportViewer..
Why this is the answer
The correct answer is to install the OS Config agent and grant the analyst roles/osconfig.vulnerabilityReportViewer. The OS Config agent (which is pre-installed on most Google-provided OS images) collects inventory and vulnerability data. The vulnerabilityReportViewer role provides specific, read-only access to this vulnerability information, directly addressing the analyst's need for visibility into OS vulnerabilities and metadata without granting broader permissions. Installing the Ops Agent and creating a custom Cloud Monitoring metric (first incorrect option) is for collecting general metrics and logs, not specific OS vulnerability data. Installing the Ops Agent and granting roles/osconfig.inventoryViewer (second incorrect option) would only provide inventory information, not vulnerability reports. Installing the OS Config agent, creating a log sink to BigQuery, and granting access to that dataset (fourth incorrect option) is an overly complex and indirect method; the vulnerabilityReportViewer role provides direct access to the required data.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed