GCP Professional Cloud Security Engineer Practice Question

Your security team must retain a complete record of every IAM policy change across all projects and all data read or write operations on BigQuery datasets tagged pii=true. You created an aggregated sink at the organization level that exports every Cloud Audit Log entry (Admin Activity, Data Access, System Event, and Policy Denied) to a long-term BigQuery dataset, but the billing team reports a sharp rise in Cloud Logging charges. What should you do to reduce logging costs while still meeting the CISO's requirements?

  • Disable System Event audit logs at the organization level because they are high-volume and billable; keep all other audit log types in the export.

  • Modify the aggregated sink's filter to export all ADMIN_ACTIVITY logs plus only DATA_READ and DATA_WRITE audit logs whose resource.type is bigquery_dataset and whose dataset label pii equals true.

  • Remove POLICY_DENIED audit logs from the export because they incur ingestion charges and are not needed for the compliance requirement.

  • Keep the existing sink but shorten log retention in Cloud Logging to one week, then rely on the BigQuery export for long-term storage.

GCP Professional Cloud Security Engineer
Managing operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot