🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 26 minutes remaining!

GCP Associate Cloud Engineer Practice Question

The security team must analyze VPC Flow Logs from every current and future project. All flow logs should be copied to a regional log bucket named flow-hub in a central security project, where they will be queried with Log Analytics. The team does not want to create or modify sinks when new projects are created. Which approach meets these requirements with the least operational effort?

  • In every project, enable VPC Flow Logs and create a sink that exports them to a BigQuery dataset in the security project, configuring another job to transfer new projects automatically.

  • Create an organization-level aggregated sink with includeChildren that filters for VPC Flow Logs only, set the destination to the flow-hub log bucket in the security project, then upgrade that bucket to Log Analytics.

  • Create a log-based metric for VPC Flow Logs and schedule a Dataflow pipeline to stream matching log entries from each project's _Default bucket into a BigQuery table.

  • Configure a Pub/Sub topic to receive all logs, write a Cloud Function that filters VPC Flow Logs and writes them to the flow-hub bucket, then query the data with BigQuery.

GCP Associate Cloud Engineer
Ensuring successful operation of a cloud solution
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot