🔥 40% Off Crucial Exams Memberships — Deal ends today!

44 minutes, 54 seconds remaining!

GCP Professional Cloud Security Engineer Practice Question

A security engineer notices repeated "error: PERMISSION_DENIED" responses in an application that calls Cloud Storage, but the project's Admin Activity and Data Access audit logs show no matching entries. To trace the root cause, the engineer wants to rely on Policy Denied audit logs. Which statement correctly describes how these logs behave in Google Cloud Logging and helps the engineer decide on next steps?

  • They require per-service opt-in similar to Data Access audit logs; the engineer must enable Policy Denied logging for Cloud Storage before entries will appear.

  • They are automatically promoted to Cloud Monitoring alert policies, so the engineer should check the Monitoring alert history instead of Cloud Logging.

  • They are generated only when IAM denial conditions block access; Organization Policy or VPC Service Controls blocks are logged as Data Access events that must be enabled first.

  • They are always written to Cloud Logging for every Google Cloud service at no additional cost and cannot be disabled, so the engineer can immediately query them to see which security policy blocked the calls.

GCP Professional Cloud Security Engineer
Managing operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot