Google Cloud Security Command Center – SCC
- Security Command Center (SCC) is Google Cloud’s comprehensive security and risk management platform.
- SCC helps generate curated insights that provide a unique view of incoming threats and attacks to the assets.
- Assets include organizations, projects, folders, instances, and applications.
- SCC displays possible security risks, called findings, that are associated with each asset.
- Findings come from security sources that include SCC’s built-in services (Security Health Analytics, Event Threat Detection, Container Threat Detection, Virtual Machine Threat Detection, Cloud Run Threat Detection), integrated services like Sensitive Data Protection and Web Security Scanner, third-party partners, and custom security detectors.
- SCC is available in three service tiers: Standard, Premium, and Enterprise.
- SCC supports multicloud environments — connecting to AWS and Azure for threat detection, vulnerability assessment, and misconfiguration detection (Enterprise tier).
- As of December 2024, new SCC activations must use V2 of the Security Command Center API only.
Security Command Center Service Tiers
- Standard — Basic security and compliance posture management for Google Cloud. Offered at no additional charge. Includes limited Security Health Analytics detectors and basic vulnerability scanning.
- Premium — Everything in Standard, plus advanced security posture management, attack path simulations, full threat detection (Event Threat Detection, Container Threat Detection, Virtual Machine Threat Detection), compliance monitoring, and Security Health Analytics with all detectors. Available at organization or project level.
- Enterprise — Complete multi-cloud CNAPP (Cloud-Native Application Protection Platform) security including Google Security Operations (SIEM/SOAR) integration, case management, playbooks, CIEM, Mandiant Attack Surface Management, and multicloud support (AWS, Azure).
⚠️ SCC Enterprise Tier Deprecation
The Security Command Center Enterprise service tier was deprecated on May 21, 2026, and will shut down on or after May 21, 2027.
Organizations using the Enterprise tier will automatically move to the Premium tier on or after the shutdown date. Contact your Google Cloud account representative for migration guidance.
Security Command Center Features
Asset Discovery and Inventory
- Discover assets, data, and Google Cloud services across the organization and view them in one place.
- Asset management in SCC now leverages Cloud Asset Inventory for asset queries and discovery.
- Note: The legacy SCC Asset API endpoints were deprecated (June 2023) and shut down (June 2024). Use Cloud Asset Inventory for asset management operations.
Sensitive Data Identification
- Sensitive Data Protection (formerly Cloud Data Loss Prevention/Cloud DLP) integrates with SCC.
- Sensitive Data Protection discovery provides continuous data monitoring to identify where sensitive data resides across BigQuery, Cloud Storage, and Datastore.
- Identify which storage buckets contain sensitive and regulated data.
- Prevent unintended exposure and ensure access is on need-to-know basis.
Application Vulnerability Detection
- Web Security Scanner integrates automatically with SCC.
- Uncover common vulnerabilities like cross-site scripting (XSS), outdated libraries, mixed content, and other OWASP Top Ten vulnerabilities.
Access Control Monitoring
- Help ensure the appropriate access control policies are in place across the Google Cloud resources and get alerted when policies are misconfigured or unexpectedly change.
- Cloud Infrastructure Entitlement Management (CIEM) identifies principal accounts that are misconfigured, have excessive permissions, or are granted sensitive permissions (Enterprise tier).
Threat Detection
- Identify threats like botnets, cryptocurrency mining, anomalous reboots, suspicious network traffic, malware, and identity-based attacks with built-in detection technology.
- Multiple specialized threat detection services provide layered defense (see SCC Services section below).
Third-party Security Tool Inputs
- Integrate output from existing security tools like Cloudflare, CrowdStrike, Prisma Cloud by Palo Alto Networks, Qualys, and others into SCC.
- Integrating output can help detect:
- DDoS attacks
- Compromised endpoints
- Compliance policy violations
- Network attacks
- Instance vulnerabilities and threats
Real-time Notifications and Exports
- Get SCC alerts through Pub/Sub notification integration.
- Continuous Exports to Pub/Sub, BigQuery, and Cloud Logging for automated finding management.
- Real-time chat notifications via email, SMS, or messaging platforms.
Security Command Center Services
- Security Health Analytics provides managed vulnerability assessment scanning that automatically detects the highest severity vulnerabilities and misconfigurations across Google Cloud assets. Supports custom modules for organization-specific detectors. Maps detectors to compliance standards (NIST, HIPAA, PCI-DSS, CIS).
- Web Security Scanner — custom and managed scans provide information about application vulnerability findings like outdated libraries, cross-site scripting, mixed content, and additional OWASP Top Ten detectors (Premium/Enterprise).
- Sensitive Data Protection (formerly Cloud DLP) — discovers, classifies, and protects sensitive data across BigQuery, Cloud Storage, and Datastore.
- Google Cloud Armor — protects Google Cloud deployments against threats like DDoS attacks, XSS, and SQL injection.
- Event Threat Detection — monitors the organization’s Cloud Logging stream to detect threats including Malware, Cryptomining, Brute Force SSH, credential leaks, IAM anomalies, data exfiltration, and more. Supports custom modules for custom threat detection rules.
- Container Threat Detection — detects runtime attacks in Container-Optimized OS node images on GKE, including malicious binaries, reverse shells, and container escapes.
- Virtual Machine Threat Detection (VMTD) — scans Compute Engine VMs at the hypervisor level without requiring agents to detect cryptomining, kernel-mode rootkits, and malware. Also supports AWS EC2 instances.
- Cloud Run Threat Detection — detects runtime attacks in Cloud Run containers, including malicious binaries, reverse shells, fileless execution, and container escapes (Premium/Enterprise).
- Agent Platform Threat Detection (Preview) — detects runtime attacks on agents deployed and managed through Agent Runtime, including credential theft, code execution, and data exfiltration by AI agents.
- Sensitive Actions Service — detects actions taken in Google Cloud that could be damaging if performed by a malicious actor (Premium/Enterprise).
- Anomaly Detection — identifies security anomalies for projects and VM instances, like potential leaked credentials and cryptocurrency mining.
Advanced Security Features (Premium/Enterprise)
Attack Path Simulations and Risk Assessment
- Attack Path Simulations identify and prioritize vulnerability and misconfiguration findings by simulating paths an attacker could take to reach high-value resources.
- Attack Exposure Scores help prioritize remediation by quantifying risk to high-value resources.
- Toxic Combinations detect groups of risks that, when occurring together, create exploitable paths to high-value resources. Uses virtual red teaming to discover previously unseen attack combinations.
- Risk Reports provide downloadable reports on the organization’s risk posture.
Security Posture Management
- Security Posture allows defining and deploying security postures to monitor security status, address posture drift, and detect unauthorized changes.
- Includes predefined posture templates for CIS Benchmark, ISO 27001, NIST 800-53, PCI DSS, and secure AI.
- Infrastructure as Code (IaC) Validation — validates Terraform plans against organization policies and Security Health Analytics detectors before deployment.
AI Protection and Model Armor
- AI Protection helps manage security posture for AI workloads by detecting threats and mitigating risks to the AI asset inventory.
- Model Armor screens LLM prompts and responses for security and safety risks, protecting against prompt injection, sensitive data leakage, and harmful content.
- Agent Platform Threat Detection detects threats specific to agentic AI workloads, including credential theft, unauthorized API calls, and data exfiltration by AI agents.
Gemini in Security Command Center
- Gemini AI provides natural language summaries of findings and recommended remediation steps.
- AI-powered investigation assistance helps security teams understand and respond to threats faster.
- Supports natural language queries for finding analysis.
Compliance Management
- Compliance Manager — define, deploy, monitor, and audit controls and frameworks for security and compliance obligations.
- Data Security Posture Management (DSPM) — evaluate, deploy, and audit data security frameworks to govern access and use of sensitive data.
- Supports frameworks including CIS Controls v8, CIS GCP Foundations Benchmark, NIST 800-53, ISO 27001, PCI DSS, and HIPAA.
Multicloud Support (Enterprise Tier)
- Connect to AWS and Azure for configuration and resource data collection.
- Detect threats, vulnerabilities, and misconfigurations across multiple cloud providers.
- Attack exposure scores and attack paths work for external cloud high-value resources.
- Vulnerability Assessment for AWS detects vulnerabilities in Amazon EC2 instances and ECR images.
- Cloud Infrastructure Entitlement Management (CIEM) identifies misconfigured identities across cloud providers.
Web Security Scanner
- Web Security Scanner identifies security vulnerabilities in App Engine, Google Kubernetes Engine (GKE), and Compute Engine web applications.
- Web Security Scanner crawls the application, following all links within the scope of the starting URLs, and attempts to exercise as many user inputs and event handlers as possible.
- Web Security Scanner only supports public URLs and IPs that aren’t behind a firewall.
- Web Security Scanner errs on the side of underreporting and doesn’t display low confidence alerts, to avoid distraction with false positives.
- It does not replace a manual security review, and it does not guarantee that the application is free from security flaws.
- Web Security Scanner managed scans are configured and managed by Security Command Center and scan public web endpoints for vulnerabilities weekly (Premium/Enterprise tier).
- Web Security Scanner custom scans allow scheduling and running custom scans on deployed applications (all tiers).
- Detects vulnerabilities including XSS, outdated libraries, clear-text passwords, mixed content, and additional OWASP Top Ten categories (Premium/Enterprise).
Deprecated and Removed Features
- Forseti Security — The open-source security toolkit has been archived and is no longer maintained by Google. Use SCC’s built-in Security Health Analytics and security posture management.
- Rapid Vulnerability Detection — Preview service was deprecated (May 2024) and shut down (July 2024).
- SCC Asset API — Legacy asset management endpoints deprecated (June 2023) and shut down (June 2024). Use Cloud Asset Inventory instead.
- Security marks for asset allowlists — No longer affects Security Health Analytics processing after April 2025. Use mute rules instead.
- SCC Enterprise tier — Deprecated May 21, 2026. Will shut down on or after May 21, 2027. Organizations will move to Premium tier.
- Anomaly Detection (standalone) — Being replaced by more specialized detection services (Event Threat Detection, VM Threat Detection).
GCP Certification Exam Practice Questions
- Questions are collected from Internet and the answers are marked as per my knowledge and understanding (which might differ with yours).
- GCP services are updated everyday and both the answers and questions might be outdated soon, so research accordingly.
- GCP exam questions are not updated to keep up the pace with GCP updates, so even if the underlying feature has changed the question might not be updated
- Open to further feedback, discussion and correction.
- Your organization needs to detect cryptocurrency mining on Compute Engine VMs without installing any agents. Which SCC service should you enable?
- Event Threat Detection
- Container Threat Detection
- Virtual Machine Threat Detection
- Security Health Analytics
Show Answer
Answer: c – Virtual Machine Threat Detection (VMTD) operates at the hypervisor level and can detect cryptomining, rootkits, and malware without requiring guest-level agents.
- Which SCC feature identifies groups of security issues that, when combined, create exploitable attack paths to high-value resources?
- Security Health Analytics
- Toxic Combinations
- Event Threat Detection
- Anomaly Detection
Show Answer
Answer: b – Toxic Combinations detects groups of risks that, when occurring together in a particular pattern, create a path to high-value resources that an attacker could potentially exploit.
- Your organization wants to detect runtime attacks in Cloud Run containers. Which SCC service provides this capability?
- Container Threat Detection
- Cloud Run Threat Detection
- Event Threat Detection
- Web Security Scanner
Show Answer
Answer: b – Cloud Run Threat Detection specifically detects runtime attacks in Cloud Run containers, including malicious binaries, reverse shells, and fileless execution.
- Which SCC service tier provides multicloud support for detecting threats and vulnerabilities in AWS and Azure environments?
- Standard
- Premium
- Enterprise
- All tiers
Show Answer
Answer: c – The Enterprise tier provides multicloud CNAPP security with support for AWS and Azure environments, including threat detection, vulnerability assessment, and misconfiguration detection.
- Your organization needs to protect AI/LLM workloads from prompt injection attacks and sensitive data leakage. Which SCC service should you use?
- AI Protection
- Model Armor
- Sensitive Data Protection
- Event Threat Detection
Show Answer
Answer: b – Model Armor screens LLM prompts and responses for security and safety risks, specifically protecting against prompt injection, sensitive data leakage, and harmful content.
- Which statement about SCC’s asset management is correct as of 2024?
- SCC provides its own Asset API for querying all organization assets
- Asset discovery runs every hour automatically
- Cloud Asset Inventory should be used for asset management operations
- Forseti Security handles all asset monitoring
Show Answer
Answer: c – The legacy SCC Asset API was deprecated and shut down in 2024. Cloud Asset Inventory is now the recommended service for asset management operations.
- Which SCC feature validates Terraform configurations against security policies before deployment?
- Security Posture
- Infrastructure as Code (IaC) Validation
- Security Health Analytics custom modules
- Compliance Manager
Show Answer
Answer: b – IaC Validation validates Terraform plans against organization policies and Security Health Analytics detectors before deployment, catching misconfigurations before resources are created.
- What happens to organizations using the SCC Enterprise tier after May 21, 2027?
- They lose all SCC access
- They are automatically moved to the Standard tier
- They are automatically moved to the Premium tier
- They must purchase a new license
Show Answer
Answer: c – The SCC Enterprise tier was deprecated on May 21, 2026, and will shut down on or after May 21, 2027. Organizations will automatically move to the Premium tier.