🔥 40% Off Crucial Exams Memberships — Deal ends today!

4 minutes, 28 seconds remaining!

GCP Professional Cloud Security Engineer Practice Question

Your company has hundreds of Google Cloud projects under a single organization. Security operations requires that every Admin Activity audit log entry and every VPC firewall rules log entry from any project be stored in a central BigQuery dataset for long-term analysis. Duplicate log entries must be avoided, and project owners must not be able to disable or change the export configuration. Which solution meets these requirements?

  • Create a non-intercepting aggregated log sink at the organization level with includeChildren=true and a filter that selects Admin Activity and firewall rule logs, routing them to a BigQuery dataset in a central logging project. Grant the organization-level Cloud Logging service account permission to write to the dataset.

  • Create an intercepting aggregated sink on the folder that contains most projects, export all logs to BigQuery, and deduplicate events in queries when necessary.

  • Create identical log sinks in every project that export all logs to the same BigQuery dataset and restrict project owners from editing their sinks through organization-level IAM policies.

  • Enable Data Access audit logs organization-wide, create a global Pub/Sub log sink, stream all logs to Cloud Dataflow, and have Dataflow write only Admin Activity and firewall logs to BigQuery after removing duplicates.

GCP Professional Cloud Security Engineer
Managing operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot