GCP Professional Cloud Security Engineer Practice Question

Your organization stores sensitive customer records in several Cloud Storage buckets within the production project. A new regulation requires that every API call which reads or writes object data in these buckets be logged and retained for a year. Admin Activity audit logs are already collected automatically for all services. You are asked to satisfy the new requirement while avoiding unnecessary log volume and charges for other Google Cloud services. Which configuration should you apply?

  • Turn on VPC Flow Logs for the subnet that hosts the Cloud Storage buckets to capture read and write operations.

  • Enable Data Access audit logging for all services at the organization level so every API call in every project is captured.

  • Create a log sink that exports existing Admin Activity audit logs for the project to BigQuery for long-term retention.

  • Update the project's IAM policy to add an AuditConfig that enables only DATA_READ and DATA_WRITE logs for the service "storage.googleapis.com".

GCP Professional Cloud Security Engineer
Managing operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot