professional-cloud-data-engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise operates a multitenant data lake on Google Cloud using Cloud Storage and BigQuery to process sensitive analytics workloads. The security team requires a centralized monitoring strategy to detect unauthorized activities, identify anomalous Identity and Access Management (IAM) privilege escalations, and track defense evasion attempts—such as unauthorized modifications to VPC Service Controls perimeters or disabling secure transport policies on storage buckets.
Which solution should you implement to meet these security monitoring and data governance requirements?
Security Command Center (SCC) Event Threat Detection is a built-in threat detection engine that continuously analyzes stream logs—including Cloud Audit Logs, IAM Admin Activity logs, and Data Access audit logs—to identify suspicious activities, policy violations, and advanced security threats across Google Cloud environments.
DATA_READ logging on Cloud Storage and BigQuery ensures that all object reads, queries, and data retrievals are recorded for compliance and governance visibility.storage.secureHttpTransport policies on storage buckets.Leveraging native Security Command Center Event Threat Detection alongside Data Access audit logs provides turnkey, managed threat detection and compliance logging without the operational overhead of building, scaling, and maintaining custom log-parsing pipelines.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.