GCP Professional Cloud Architect Practice Question

An online payment processor is migrating workloads to Google Cloud. To satisfy PCI DSS requirements and an internal mandate to keep all Admin Activity and Data Access logs for seven years, the security team must guarantee that the logs cannot be modified or deleted by platform administrators while keeping storage costs low. Which design best meets these requirements?

  • Create an aggregated organization-level log sink that routes all Admin Activity and Data Access logs to a Cloud Storage bucket in a dedicated logs project. Enable uniform bucket-level access, configure a seven-year retention policy, lock the bucket (Bucket Lock), and grant only the Logs Router service account the objectCreator role.

  • Export all Audit Logs to a BigQuery dataset in the same project, set table expiration to seven years, and restrict modifications by granting the audit team the BigQuery Data Viewer role only.

  • Rely on Cloud Logging's default 400-day retention and grant the audit team the Logs Viewer role on each project; when older records are needed, export them on demand to BigQuery.

  • Stream Audit Logs to Pub/Sub and forward them over VPN to the company's on-premises SIEM, then configure Cloud Logging to delete local copies after 30 days to reduce costs.

GCP Professional Cloud Architect
Designing for security and compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot