🔥 40% Off Crucial Exams Memberships — Deal ends today!

44 minutes, 59 seconds remaining!

GCP Associate Cloud Engineer Practice Question

Your security team must track which users read or modify objects in Cloud Storage for compliance. Admin Activity audit logs are already collected, but Data Access audit logs are still missing. What is the most appropriate way to start collecting both DATA_READ and DATA_WRITE logs for the Cloud Storage service at the project level while minimizing operational overhead?

  • Update the project IAM policy to include an auditConfig for service "storage.googleapis.com" with log types DATA_READ and DATA_WRITE.

  • Enable the Cloud Audit Logs API and grant all users the Cloud Audit Logs Viewer role.

  • Enable uniform bucket-level access on the bucket and turn on Object Viewer logging in the bucket's permissions tab.

  • Create a log sink to route existing _Default bucket entries to BigQuery for long-term storage.

GCP Associate Cloud Engineer
Ensuring successful operation of a cloud solution
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot