GCP Professional Cloud Security Engineer Practice Question

Your organization has an org-level aggregated Cloud Logging sink exporting all audit logs to BigQuery. After a breach, you confirm that several objects were downloaded from the sensitive Cloud Storage bucket in project "prod-secure." The dataset shows recent Admin Activity entries (such as bucket IAM changes) but no records identifying who read the objects. No log exclusions exist, and the sink filter already includes all logs. What most likely explains the missing read events, and what single configuration change will ensure they are logged going forward?

  • Cloud Storage records object downloads only in legacy bucket access logs; you need to enable Access Logs at the bucket level to capture future reads.

  • Data Access audit logs for Cloud Storage are disabled by default; you must explicitly enable the DATA_READ (and optionally DATA_WRITE) audit log type for the prod-secure project or higher so future object downloads are logged and exported.

  • Organization-level aggregated sinks cannot export Data Access audit logs; you must create separate project-level sinks in prod-secure to forward these events.

  • Object download events are written to VPC Flow Logs, which were never enabled for the subnet where the bucket's VM clients reside; turning on flow logs will provide the missing information.

GCP Professional Cloud Security Engineer
Managing operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot