GCP Professional Cloud Security Engineer Practice Question
Your organization processes cardholder data in a dedicated Google Cloud project. The compliance team requires that you
capture every change to IAM policies across the project, and
log all successful and failed reads and writes to the Cloud Storage bucket that stores cardholder data. To reduce log-ingestion cost, they want to collect only the minimum additional audit logs needed. Which logging configuration best satisfies these requirements while minimizing extra log volume?
Enable Data Access audit logs for every service in the project and disable Admin Activity logs to avoid duplicate entries, then export all audit logs to Cloud Storage.
Enable System Event audit logs for the project and configure them to include data reads and writes, then export those logs for retention.
Enable Data Access audit logs for Cloud Storage at the project level and create a sink that exports only entries for the cardholder-data bucket; rely on the always-on Admin Activity audit logs for IAM policy changes.
Rely solely on Admin Activity audit logs, because they already capture both IAM policy changes and Cloud Storage object reads and writes.
Admin Activity audit logs are generated for every Google Cloud service and cannot be disabled, so they already capture all IAM policy changes without any additional configuration. Data Access audit logs record object read and write operations in Cloud Storage, but they are disabled by default because of their high volume and cost. Enabling Data Access logging for Cloud Storage at the project level activates those logs for all buckets, after which a log sink can filter and export only the entries whose resource name corresponds to the sensitive bucket. This yields the required evidence for cardholder-data access while keeping other Data Access logs from being stored. System Event logs capture Google-initiated infrastructure changes, not user data access, and cannot be enabled or disabled. Admin Activity logs cannot be configured at the bucket level, and they do not include object data reads or writes. Therefore, enabling Cloud Storage Data Access logs and relying on the always-on Admin Activity logs is the only option that meets the compliance goals with the least extra logging.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are Admin Activity audit logs in Google Cloud?
Open an interactive chat with Bash
What are Data Access audit logs, and why are they disabled by default?
Open an interactive chat with Bash
How do log sinks help minimize costs in Google Cloud logging?
Open an interactive chat with Bash
What are Admin Activity audit logs in Google Cloud?
Open an interactive chat with Bash
What are Data Access audit logs, and why are they disabled by default?
Open an interactive chat with Bash
How do log sinks work in Google Cloud, and why are they used in this case?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Supporting compliance requirements
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .