🔥 40% Off Crucial Exams Memberships — Deal ends today!

4 minutes, 54 seconds remaining!

GCP Professional Cloud Security Engineer Practice Question

Your organization processes cardholder data in a dedicated Google Cloud project. The compliance team requires that you

  1. capture every change to IAM policies across the project, and
  2. log all successful and failed reads and writes to the Cloud Storage bucket that stores cardholder data. To reduce log-ingestion cost, they want to collect only the minimum additional audit logs needed. Which logging configuration best satisfies these requirements while minimizing extra log volume?
  • Enable Data Access audit logs for every service in the project and disable Admin Activity logs to avoid duplicate entries, then export all audit logs to Cloud Storage.

  • Enable System Event audit logs for the project and configure them to include data reads and writes, then export those logs for retention.

  • Enable Data Access audit logs for Cloud Storage at the project level and create a sink that exports only entries for the cardholder-data bucket; rely on the always-on Admin Activity audit logs for IAM policy changes.

  • Rely solely on Admin Activity audit logs, because they already capture both IAM policy changes and Cloud Storage object reads and writes.

GCP Professional Cloud Security Engineer
Supporting compliance requirements
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot