GCP Professional Cloud Security Engineer Practice Question

Your organization runs hundreds of GCP projects. A recent security incident involved the public exposure and download of sensitive Cloud Storage objects. Event Threat Detection flagged the exposure, but the incident response team could not determine which IAM principal actually downloaded the data because the required log entries were missing. During the post-mortem you must recommend a preventive action that both improves future investigations and enables centralized analysis while limiting operational overhead. What should you propose?

  • Enable DEBUG-level logging on all storage buckets and retain application logs locally in each project for 7 years.

  • Enable Data Access audit logs for Cloud Storage at the organization level and create an aggregated log sink that exports these logs to a centrally managed BigQuery dataset with partitioned, 1-year retention for analysis.

  • Configure Packet Mirroring for all VPCs and send traffic to Cloud IDS; disable Data Access audit logs to avoid duplicate logging charges.

  • Turn on VPC Flow Logs for every subnet and export them to Cloud Storage; rely on the source IP address to identify future data exfiltration events.

GCP Professional Cloud Security Engineer
Managing operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot