🔥 40% Off Crucial Exams Memberships — Deal ends today!

9 minutes, 34 seconds remaining!

GCP Professional Cloud Architect Practice Question

Your company must satisfy a new regulatory mandate: every Google Cloud project's Admin Activity and Data Access audit logs must be preserved in an immutable (write-once-read-many) store for at least seven years. Security investigators also need near-real-time SQL access to the most recent 12 months of those logs. You are designing the logging architecture for hundreds of existing and future projects and want to minimize long-term operational effort. Which approach best meets all requirements?

  • Enable a 2555-day custom retention policy on every project's default logging bucket and give security investigators the Logging Private Logs Viewer role so they can query required data in Logs Explorer.

  • Export all audit logs to an on-premises Splunk cluster via Pub/Sub, retain the data there for seven years, and allow investigators to run searches through Splunk's interface.

  • Configure per-project log sinks that publish Admin Activity and Data Access logs to Pub/Sub, stream them into Cloud Bigtable, and schedule a Dataflow job to delete records older than seven years while investigators query the data through Bigtable.

  • Create two aggregated organization-level log sinks with identical filters: route one sink to a CMEK-encrypted BigQuery dataset in a dedicated security project for 12-month interactive queries, and route the other sink to a Cloud Storage bucket in the same project with Object Versioning and a seven-year Bucket Lock; grant write access only to the Log Router service account.

GCP Professional Cloud Architect
Designing for security and compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot