GCP Professional Cloud Security Engineer Practice Question

Your organization operates a multi-project GCP environment aligned with separate business units. Security engineers want to aggregate all Admin Activity, Data Access, VPC Flow, and application logs into a dedicated "sec-logs" project they own, while preserving least-privilege: individual developers must continue to see only the logs that originate from their own projects, and not the logs of other teams. Which architecture best satisfies these requirements with minimal operational overhead?

  • Configure a VPC Service Controls perimeter that contains all projects and rely on default aggregated audit logging; assign the Logging Private Log Viewer role to developers so they are automatically limited to their own project's logs.

  • Enable Cloud Logging in every project and write logs to individual BigQuery datasets. Share each dataset with the security team and run scheduled queries that union all datasets into a consolidated dataset inside the sec-logs project.

  • Create an aggregated sink at the organization level that routes all logs to a log bucket in the sec-logs project. Grant the security team Logging Viewer on that bucket and create project-specific log views that restrict each development team to only their project's logs.

  • Export each project's logs to its own Cloud Storage bucket, enable bucket-level Object ACLs for the development teams, and use Transfer Service to copy the objects nightly to the sec-logs project.

GCP Professional Cloud Security Engineer
Managing operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot