🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 26 minutes remaining!

GCP Associate Cloud Engineer Practice Question

Your security team mandates that all Admin Activity and Data Access audit logs from the production project be archived in a dedicated Cloud Storage bucket for at least seven years. You create a log sink called prod-audit-archive with the following settings:

  • Destination: gs://prod-audit-logs
  • Inclusion filter: logName:("cloudaudit.googleapis.com%2Factivity" OR "cloudaudit.googleapis.com%2Fdata_access")

After 24 hours no new objects appear in the bucket. What additional action is required to make sure the sink can deliver log entries to the bucket while preserving least-privilege access?

  • Grant the sink's writer identity the Storage role allowing it to create objects (for example, roles/storage.objectCreator) on the prod-audit-logs bucket.

  • Set a bucket lifecycle rule that prevents object deletion for seven years.

  • Recreate the sink using a Cloud Storage URI that ends with /** to match all object prefixes.

  • Enable Requester Pays on the prod-audit-logs bucket so Cloud Logging is billed for writes.

GCP Associate Cloud Engineer
Ensuring successful operation of a cloud solution
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot