GCP Professional Cloud Architect Practice Question

Your organization needs to build a centralized log sink that collects only the entries created when Google Cloud performs automatic actions such as Compute Engine live-migration, hypervisor maintenance, or automatic node restarts. The security team also wants to guarantee that these entries are always written, even if individual project administrators change their own logging configurations, and that the logs do not incur additional ingestion charges. Which Cloud Audit Logs type should you specify in the sink's inclusion filter, and why?

  • Policy Denied audit logs - they record system-generated denial events and cannot be disabled, so they will include the needed maintenance actions.

  • Admin Activity audit logs - they capture all configuration changes by users and are always enabled, ensuring the required events are logged.

  • Data Access audit logs - they track metadata and data reads or writes and are generated without charge when enabled across projects.

  • System Event audit logs - they are written for platform-initiated actions, are always enabled, and are ingested at no additional cost.

GCP Professional Cloud Architect
Designing for security and compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot