🔥 40% Off Crucial Exams Memberships — Deal ends today!

4 minutes, 28 seconds remaining!

GCP Professional Cloud Security Engineer Practice Question

A security team must gain near-real-time insight into who is reading objects stored in a sensitive Cloud Storage bucket. The organization already collects Cloud Audit Logs for Admin Activity but no Data Access records appear when engineers download objects from this bucket. As the Cloud Security Engineer, you need to start logging these read events and make them queryable in BigQuery while following the principle of least privilege and minimizing operational overhead. What should you do?

  • Grant the security analysts the roles/logging.privateLogViewer role on the source project and create a sink that exports existing Admin Activity logs to BigQuery; Data Access reads will appear automatically once the sink is active.

  • Create a Cloud Monitoring metric based on the metric type logging.googleapis.com/user/data_access and configure an alerting policy that writes matching entries to BigQuery via Pub/Sub.

  • Enable the Storage 'Read' Data Access audit logs on the project and configure a project-level log sink that exports entries with logName="cloudaudit.googleapis.com/data_access" AND resource.type="gcs_bucket" to a BigQuery dataset in a centralized logging project. Grant the security analysts BigQuery Data Viewer on that dataset.

  • Attach the primitive roles/owner role to the security team so they can view all audit logs directly in Logs Explorer; no additional configuration is required because Data Access logs are always on for Cloud Storage.

GCP Professional Cloud Security Engineer
Managing operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot