GCP Professional Cloud Security Engineer Practice Question
Your organization runs hundreds of projects. Cloud IDS threat detection (fed by Packet Mirroring) and VPC Flow Logs are enabled in every project. The security operations team wants to correlate IDS threat events with flow-level network metadata using familiar SQL queries. They must keep the data for 18 months and want to minimize operational overhead by avoiding custom ETL jobs or separate BigQuery datasets. Which solution best meets these requirements?
Enable the Cloud IDS BigQuery export feature and add a second sink that exports VPC Flow Logs to the same BigQuery dataset; configure table partition expiration for 550 days.
Stream both Cloud IDS and VPC Flow Logs to Pub/Sub, process them with a Dataflow pipeline that writes to BigQuery, and schedule a job to delete partitions older than 550 days.
Create an organization-level aggregated log sink that routes Cloud IDS and VPC Flow Logs into a dedicated log bucket, enable Log Analytics on that bucket, set the bucket retention to 550 days, and grant analysts read-only Logging IAM roles.
Forward Cloud IDS alerts to Chronicle and export VPC Flow Logs to Cloud Storage; query the combined data through Chronicle's YARA-L interface.
Both Cloud IDS logs and VPC Flow Logs are ingested into Cloud Logging. By creating an organization-level aggregated sink that routes all relevant log entries to a centralized log bucket, you guarantee a single storage location across projects. Upgrading that bucket to Log Analytics activates the built-in BigQuery execution engine, letting analysts run standard SQL directly against the logs without exporting them. The bucket's retention can be configured to any value between 1 and 3650 days, so setting it to roughly 550 days satisfies the 18-month archive requirement. Granting read-only Logging roles on the bucket enforces least-privilege access. The other options either require managing external BigQuery datasets, additional ETL pipelines, or use products (Chronicle, Cloud Trace) that do not natively satisfy the stated constraints.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Log Analytics in Cloud Logging?
Open an interactive chat with Bash
What is an aggregated log sink in GCP?
Open an interactive chat with Bash
How does Packet Mirroring support Cloud IDS?
Open an interactive chat with Bash
What is Cloud IDS and how does it integrate with Packet Mirroring?
Open an interactive chat with Bash
What is an aggregated log sink in Google Cloud?
Open an interactive chat with Bash
How does Log Analytics with a centralized log bucket enable SQL querying?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Managing operations
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .