🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 50 minutes remaining!

GCP Professional Cloud Security Engineer Practice Question

Your company recently acquired two other businesses and now manages more than 120 Google Cloud projects under a single organization node. Security policy requires that:

  • All audit and network logs from every project must be retained for exactly seven years.
  • Only members of the central security team may view the raw log entries.
  • Security engineers need to run ad-hoc SQL queries against recent findings without moving data to another service.
  • Logging costs should be minimized and managed in one place. Which logging architecture best meets these requirements?
  • Create an organization-level aggregated sink that routes all logs to a dedicated log bucket in a central "security-logs" project, set the bucket's retention to seven years, enable Log Analytics on the bucket, and grant only the security team roles/logging.privateLogViewer access.

  • In every project, configure a sink that exports only Admin Activity logs to a Cloud Storage bucket with a seven-year lifecycle rule, then mount the bucket to the SIEM; give developers read-only access to the bucket.

  • Enable Data Access logs for all services and stream every log entry to Pub/Sub, forwarding the stream to the company's external SIEM that stores data for seven years; disable Cloud Logging storage to lower costs.

  • Create separate log buckets with seven-year retention in each project and configure folder-level aggregated sinks that copy the logs to a BigQuery dataset; grant the network engineering team roles/logging.privateLogViewer on every bucket.

GCP Professional Cloud Security Engineer
Managing operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot