🔥 40% Off Crucial Exams Memberships — Deal ends today!

3 hours, 1 minute remaining!

GCP Professional Cloud Security Engineer Practice Question

Your security operations team runs Google Cloud Security Command Center (SCC) Premium across the entire organization. Event Threat Detection has generated a high-severity finding that suggests credential exfiltration in several production projects. Per your incident-response agreement, on-call Mandiant analysts must receive the related log data within minutes so they can start triage, but they must not gain broad access to your internal logs. You also need to keep an untampered, long-term copy of all incident-related log entries for later forensic analysis. Which approach best meets these requirements?

  • Enable BigQuery log export for the impacted projects, share the dataset with the Mandiant service account, and run a scheduled Dataflow job every six hours to copy the tables to an immutable bucket.

  • Grant the Mandiant service account the Logging Viewer role on each affected project and enable real-time streaming in Logs Explorer; rely on the default Cloud Audit Logs retention for forensic preservation.

  • Provide Viewer access to the SCC dashboard at the organization level and instruct Mandiant to download any required logs directly from the console.

  • Create two aggregated organization-level log sinks with identical filters: one streams matching entries to a Pub/Sub topic in an "ir-partner" project where the Mandiant service account has only the Pub/Sub Subscriber role; the other exports the same entries to a Cloud Storage bucket that has object versioning and a locked retention policy.

GCP Professional Cloud Security Engineer
Managing operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot