GCP Professional Cloud Security Engineer Practice Question

In a centralized logging project, all project logs flow into an organization-level bucket called org-sec-logs. Requirements: 1) Tier-1 analysts must read every entry, including Data Access audit logs. 2) Each project's tech lead must see only that project's logs and must never see Data Access audit logs. 3) A compliance-automation service account must adjust bucket retention and create new log buckets and views. Which IAM and log-view configuration meets these needs with the least privilege?

  • Grant roles/logging.privateLogViewer on the logging project to both analysts and tech leads; grant roles/logging.configWriter on the org-sec-logs bucket to the compliance service account; create per-project log sinks for tech leads.

  • Grant roles/viewer at the organization level to analysts; create a per-project log view and grant roles/logging.privateLogViewer on the view to each tech lead; grant roles/logging.viewer on the org-sec-logs bucket to the compliance service account.

  • Grant roles/logging.viewer to analysts; grant roles/logging.privateLogViewer to each tech lead; grant the compliance service account the Owner role on the logging project without using log views.

  • Grant roles/logging.privateLogViewer on the org-sec-logs bucket to analysts; create a per-project log view that excludes logName entries matching data_access and grant roles/logging.viewer on that view to each tech lead; grant roles/logging.admin on the logging project to the compliance service account.

GCP Professional Cloud Security Engineer
Managing operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot