GCP Professional Cloud Security Engineer Practice Question
Your company is migrating a payment-processing platform to Google Cloud. PCI DSS requires evidence of configuration changes, records of every user access to card-holder data, and visibility into suspicious network activity. You must design a centralized, cost-effective logging architecture in which all required events from every project are exported to a single BigQuery dataset for long-term analysis. Which combination of Google Cloud log sources must you aggregate to meet the compliance requirements?
Admin Activity audit logs and System Event logs only
Admin Activity audit logs, Data Access audit logs, VPC Flow Logs, and Firewall Rules Logging
VPC Flow Logs, Cloud Trace spans, and Error Reporting logs
Data Access audit logs, Cloud Monitoring metrics, and Cloud NAT logs
To satisfy PCI DSS you need three categories of information:
Configuration or system changes ➜ captured by Admin Activity audit logs (always on).
Reads and writes of card-holder data ➜ captured by Data Access audit logs (must be explicitly enabled for most services).
Indicators of network threats ➜ captured by network telemetry such as VPC Flow Logs and Firewall Rules Logging. Exporting these four log sources from every project to an aggregated sink ensures complete visibility in a single BigQuery dataset. The other options omit at least one mandatory category (for example, they lack Data Access logs or network telemetry) or substitute logs that do not record the required events (Cloud Trace, Error Reporting, Cloud Monitoring metrics, Cloud NAT logs).
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an audit log in Google Cloud and its importance for PCI DSS compliance?
Open an interactive chat with Bash
What are VPC Flow Logs and Firewall Rules Logging, and how do they help detect threats?
Open an interactive chat with Bash
How can logs be aggregated into a single BigQuery dataset for centralized analysis?
Open an interactive chat with Bash
What are Admin Activity audit logs, and why are they essential for PCI DSS compliance?
Open an interactive chat with Bash
Why do Data Access audit logs need to be explicitly enabled for PCI DSS compliance?
Open an interactive chat with Bash
What role do VPC Flow Logs and Firewall Rules Logging play in identifying network threats for PCI DSS?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Managing operations
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .