GCP Professional Cloud Security Engineer Practice Question
Your security team stores all audit logs in a central BigQuery dataset for threat hunting. An organization-level aggregated log sink has already been created with includeChildren=true and a filter of logName:"/cloudaudit.googleapis.com". Several project-level teams are starting to create their own project sinks to export logs to Pub/Sub for near-real-time alerting. The governance group wants to avoid duplicate BigQuery ingestion charges yet still guarantee that every audit log entry for every project, including any that are not routed by a project sink, reaches the central dataset. Which configuration should you implement on the organization-level sink to meet these requirements?
Convert the sink to intercepting mode so it always copies logs before project sinks can export them.
Restrict the sink's filter to severity>=ERROR to reduce duplicates without changing interception behavior.
Keep includeChildren=true but set the sink as non-intercepting so it only exports entries not already captured by project sinks.
Disable includeChildren on the sink and ask every project to add the central BigQuery dataset as an additional destination.
An intercepting aggregated sink exports a copy of matching log entries before any child-level sinks process them. If duplicate exports are undesirable, you turn off interception so that the org-level sink only receives entries that are left un-exported by lower-level sinks. Setting the org-level aggregated sink to non-intercepting (includeChildren=true, IS_LOG_INTERCEPTION=false) prevents BigQuery duplicates, while still guaranteeing coverage for any logs a project sink misses. Making the sink intercepting would re-introduce duplication, and disabling includeChildren or changing the filter would break the central coverage objective.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the difference between an intercepting and a non-intercepting log sink in GCP?
Open an interactive chat with Bash
How does the includeChildren=true setting affect log sinks in GCP?
Open an interactive chat with Bash
What happens if an organization-level log sink's filter is modified to severity>=ERROR?
Open an interactive chat with Bash
What does 'includeChildren=true' mean in the context of log sinks?
Open an interactive chat with Bash
What is the difference between intercepting and non-intercepting sinks?
Open an interactive chat with Bash
Why is IS_LOG_INTERCEPTION=false crucial for preventing duplicates in BigQuery?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Managing operations
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .