Intrigued by the art of cloud architecture? Discover how to design, develop, and manage robust, secure, scalable, and dynamic solutions on Google Cloud as you prepare for the Professional Cloud Architect exam!
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A multinational financial services company operates multiple Google Cloud projects across several business units organized under a single Google Cloud organization. To meet strict regulatory mandates and ensure auditability, the security and compliance team has established the following architecture requirements:
europe-west3) to comply with national data residency regulations.Which logging architecture should you design to fulfill these requirements?
Create an organization-level aggregated log sink directing audit logs to a multi-region BigQuery dataset in Europe, and configure Eventarc triggers to batch export audit logs to the external SIEM.
Configure the default _Required log bucket in each project to retain logs for seven years, and run a scheduled Cloud Run job that queries the Logs API hourly to push events to Cloud Storage and the external SIEM.
Create an organization-level aggregated log sink that routes all audit logs to a regional Cloud Storage bucket located in europe-west3, and configure a second aggregated log sink that filters high-severity security events to a Pub/Sub topic to stream logs to the external SIEM.
Configure project-level log sinks in each project routing audit logs to a linked BigQuery dataset located in europe-west3, and export daily snapshots to Cloud Storage using BigQuery Data Transfer Service.
Create an organization-level aggregated log sink directing audit logs to a multi-region BigQuery dataset in Europe, and configure Eventarc triggers to batch export audit logs to the external SIEM.
Configure the default _Required log bucket in each project to retain logs for seven years, and run a scheduled Cloud Run job that queries the Logs API hourly to push events to Cloud Storage and the external SIEM.
Create an organization-level aggregated log sink that routes all audit logs to a regional Cloud Storage bucket located in europe-west3, and configure a second aggregated log sink that filters high-severity security events to a Pub/Sub topic to stream logs to the external SIEM.
This architecture uses organization-level aggregated log sinks in Cloud Logging to automatically capture audit logs from all current and future child projects. It routes long-term audit records to a regionally bound Cloud Storage bucket while routing real-time security events to a Pub/Sub topic for external SIEM streaming.
europe-west3 region guarantees that data at rest stays within the specified geographic boundary.Configure project-level log sinks in each project routing audit logs to a linked BigQuery dataset located in europe-west3, and export daily snapshots to Cloud Storage using BigQuery Data Transfer Service.