professional-cloud-data-engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise operates a multitenant data lake on Google Cloud using Cloud Storage and BigQuery to process sensitive analytics workloads. The security team requires a centralized monitoring strategy to detect unauthorized activities, identify anomalous Identity and Access Management (IAM) privilege escalations, and track defense evasion attempts—such as unauthorized modifications to VPC Service Controls perimeters or disabling secure transport policies on storage buckets.
Which solution should you implement to meet these security monitoring and data governance requirements?
Configure VPC Flow Logs across all subnets and use BigQuery scheduled queries to evaluate network telemetry for unauthorized IP addresses accessing Cloud Storage APIs.
Enable Data Access audit logs with DATA_READ enabled on the data lake storage resources, and activate Security Command Center with Event Threat Detection to analyze Cloud Audit Logs for anomalous IAM behaviors and defense evasion.
Export Cloud Storage access logs to a Cloud Logging bucket and configure Cloud Monitoring alerting policies based on custom metric counters for storage bucket metadata operations.
Deploy custom Cloud Functions triggered by Cloud Pub/Sub to parse all Admin Activity logs and execute custom scripts that revoke IAM roles whenever changes occur.
Configure VPC Flow Logs across all subnets and use BigQuery scheduled queries to evaluate network telemetry for unauthorized IP addresses accessing Cloud Storage APIs.
Enable Data Access audit logs with DATA_READ enabled on the data lake storage resources, and activate Security Command Center with Event Threat Detection to analyze Cloud Audit Logs for anomalous IAM behaviors and defense evasion.
Security Command Center (SCC) Event Threat Detection is a built-in threat detection engine that continuously analyzes stream logs—including Cloud Audit Logs, IAM Admin Activity logs, and Data Access audit logs—to identify suspicious activities, policy violations, and advanced security threats across Google Cloud environments.
DATA_READ logging on Cloud Storage and BigQuery ensures that all object reads, queries, and data retrievals are recorded for compliance and governance visibility.storage.secureHttpTransport policies on storage buckets.Leveraging native Security Command Center Event Threat Detection alongside Data Access audit logs provides turnkey, managed threat detection and compliance logging without the operational overhead of building, scaling, and maintaining custom log-parsing pipelines.
Export Cloud Storage access logs to a Cloud Logging bucket and configure Cloud Monitoring alerting policies based on custom metric counters for storage bucket metadata operations.
Deploy custom Cloud Functions triggered by Cloud Pub/Sub to parse all Admin Activity logs and execute custom scripts that revoke IAM roles whenever changes occur.