GCP Professional Cloud Security Engineer Practice Question
Your company wants to forward all Policy Denied audit logs from every project in its organization to an external SIEM that consumes messages from a Pub/Sub subscription. As a Cloud Security Engineer, what should you do to set up a scalable, tamper-resistant export while minimizing configuration overhead across projects?
Configure an organization-level aggregated sink that exports the logs to a BigQuery dataset, then schedule a Dataflow job to stream the dataset into a Pub/Sub topic consumed by the SIEM.
Enable Policy Denied audit logs and VPC Flow Logs in each project and export them with a bucket-level sink to a Cloud Storage bucket that has object versioning enabled.
Create an organization-level aggregated log sink filtered for Policy Denied audit logs, set the destination to a Pub/Sub topic in a central security project, grant the sink's service account the Pub/Sub Publisher role on that topic, and allow the SIEM to create its own subscription.
Enable Policy Denied audit logs in every project and configure a separate project-level sink in each one that exports to a local Pub/Sub topic, then share all topics with the SIEM.
Creating a single organization-level aggregated log sink with includeChildren=true centralizes log routing for every project and folder, eliminating the need to manage individual sinks. By adding a filter such as logName="cloudaudit.googleapis.com%2Fpolicy", the sink exports only Policy Denied audit logs. Pointing the sink to a Pub/Sub topic in a dedicated security project keeps the logs isolated from the source projects, reducing the risk of tampering. The sink's writer identity must be granted the roles/pubsub.publisher IAM role on the destination topic so Cloud Logging can publish messages; subscriber permissions are not required for publishing. Alternatives that rely on per-project sinks or intermediate BigQuery/Dataflow pipelines increase operational overhead and complexity, while exporting to Cloud Storage doesn't meet the SIEM's real-time Pub/Sub ingestion requirement.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an organization-level aggregated log sink in GCP?
Open an interactive chat with Bash
How does Pub/Sub help in forwarding logs to an external SIEM?
Open an interactive chat with Bash
Why is it necessary to use a filter like `logName="cloudaudit.googleapis.com%2Fpolicy"`?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Managing operations
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .