QuestionQ163

Supporting compliance requirements

For compliance reporting, the internal audit department requires a list of virtual machines (VMs) with critical operating system (OS) security updates available but not installed. You must provide this list every six months and want to complete the task quickly.

What should you do?

  • A Run a Security Command Center security scan on all VMs to extract a list of VMs with critical OS vulnerabilities every six months.
  • B Run a gcloud CLI command from the Command Line Interface (CLI) to extract the VM's OS version information every six months.
  • C Ensure that the Cloud Logging agent is installed on all VMs, and extract the OS last update log date every six months.
  • D Ensure the OS Config agent is installed on all VMs and extract the patch status dashboard every six months.
Explanation

VM Manager’s Patch dashboard provides fleet-wide patch-compliance information. Its Critical category identifies VMs that have critical updates available; VMs must have the OS Config agent installed and OS inventory management enabled to appear in the dashboard.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!