GCP Professional Cloud Security Engineer Practice Question

Your organization wants to export all Cloud Audit Logs (Admin Activity and Data Access) from every Google Cloud project to a central log bucket in a dedicated security project. Many teams already have project-level sinks that forward the same logs to other destinations, which must not receive a second copy. The security team also needs to keep exporting logs from its own project to an external SIEM and does not want its logs in the central bucket. You are asked to implement the organization-level export without asking individual teams to modify their existing sinks and while avoiding any duplicate log deliveries. What should you do?

  • In every project except the security team's, deploy a project-level sink that exports Admin Activity and Data Access logs to the central bucket, and instruct teams to remove any overlapping sinks after migration.

  • Create a non-intercepting aggregated sink at the organization level that exports Admin Activity and Data Access logs to the central bucket and uses a filter to exclude the security team's project.

  • Create an intercepting aggregated sink at the organization level with includeChildren=true. Set an advanced filter that selects all Admin Activity and Data Access logs except those whose resource.labels.project_id equals the security team's project, and route the sink to the central bucket.

  • Schedule a BigQuery Data Transfer Service job that copies Admin Activity and Data Access logs from each project's _Required log bucket into a central BigQuery dataset, then write a view to exclude the security project.

GCP Professional Cloud Security Engineer
Managing operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot