GCP Professional Cloud Architect Practice Question

Your organization operates dozens of Google Cloud projects in multiple folders. New regulatory rules mandate that all Admin Activity and Data Access audit logs must be kept for at least seven years, and once written they must be impossible for any administrator-even organization-level owners-to modify or delete. Security engineers also need read-only access to the archived logs from a central location. Which logging design best satisfies these immutability and access requirements while keeping ongoing maintenance effort low?

  • Create an organization-level aggregated log sink that exports Admin Activity and Data Access logs to a Cloud Storage bucket in a dedicated logging project; enable a seven-year retention policy on the bucket, lock the policy, allow only the Cloud Logging service account to write, and grant administrators Storage Object Viewer access.

  • Configure project-level log sinks that export Admin Activity and Data Access logs to BigQuery datasets in the same projects, set table expiration to seven years, and grant the security team BigQuery Data Viewer access.

  • Stream all audit logs to Pub/Sub and trigger Cloud Functions that write the entries into a Cloud SQL instance configured with seven-year point-in-time recovery; allow administrators read access to the database.

  • Extend the retention period of each project's _Required and _Default log buckets to 2,555 days and create an organization-level IAM deny policy that removes storage.objectDelete permissions from all users.

GCP Professional Cloud Architect
Designing for security and compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot