🔥 40% Off Crucial Exams Memberships — Deal ends today!

45 minutes, 40 seconds remaining!

GCP Professional Cloud Architect Practice Question

Your organization must retain a tamper-proof record of every IAM policy change and every successful read of objects stored in the prod-sec project for at least seven years to satisfy an upcoming PCI audit. Today, an organization-level log sink already exports only Admin Activity logs from all projects to a BigQuery dataset. Which design will meet the compliance requirement with the least additional cost and guarantee log immutability?

  • Create individual log sinks on each prod-sec Cloud Storage bucket that keep Data Access logs in Cloud Logging's default 30-day retention; instruct auditors to download logs monthly before expiration.

  • Stream all organization Audit Logs through Pub/Sub to an external SIEM that supports write-once-read-many storage, and disable the existing BigQuery sink to avoid duplicate exports.

  • Enable Cloud Storage Data Access logs for the prod-sec project, update the organization-level sink to include those logs, and route the sink to a dedicated Cloud Storage bucket that has Object Versioning plus a 7-year retention policy locked with Bucket Lock; grant auditors Storage Object Viewer on the bucket.

  • Enable Cloud Storage Data Access logs for the prod-sec project and create a new project-level sink that exports all Admin Activity and Data Access logs to a BigQuery dataset encrypted with CMEK and configured with a 7-year table expiration.

GCP Professional Cloud Architect
Designing for security and compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot