Professional Cloud DevOps Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
Your enterprise uses Google Cloud continuous integration and continuous delivery (CI/CD) pipelines to deploy microservices onto Google Kubernetes Engine (GKE) clusters. Following a security incident, the DevOps and security teams require a centralized auditing mechanism to trace all active and historical cluster deployments directly to their originating source code Git commit SHA, container artifact URI, and software package versions.
You need to implement a solution that captures this deployment metadata and allows you to programmatically inspect and analyze these audit records within Cloud Logging. What should you do?
Configure Developer Connect insights to capture deployment intelligence, and query the structured sdlc_deployment log entries in Cloud Logging to analyze commit references, artifact URIs, and package details.
Assign the roles/clouddeploy.viewer IAM role and query Cloud Audit Logs filtered by the clouddeploy.deliveryPipelines.listEffectiveTags API method.
Grant the roles/datafusion.viewer role to export Cloud Data Fusion execution metrics and query the datafusion.pipelines.get audit trail in Cloud Logging.
Enable Cloud Service Mesh authorization policies and query the server-accesslog-stackdriver log stream in Cloud Logging to extract deployment manifest headers.
Configure Developer Connect insights to capture deployment intelligence, and query the structured sdlc_deployment log entries in Cloud Logging to analyze commit references, artifact URIs, and package details.
Developer Connect insights is a Google Cloud capability that correlates software delivery lifecycle (SDLC) metadata—such as source code revisions, build artifacts, and package dependencies—with running deployment workloads across environments. It automatically persists these deployment insights into Cloud Logging as structured log entries.
commitReferences (including the exact commitSha and commit URL) and the target artifactUri in Artifact Registry.artifactDetails.packages, providing package names and package versions (e.g., specific library builds) included in the deployment.projects/PROJECT_ID/logs/developerconnect.googleapis.com/sdlc_deployment. Teams can query them via the Cloud Logging API, Logs Explorer, or the gcloud logging read command using structured filters such as labels.insights_config_id.Developer Connect insights provides fully managed, out-of-the-box extraction and correlation of SDLC metadata directly into structured Cloud Logging entries. It removes the operational burden of writing custom webhook interceptors or parsing custom build manifests manually across multiple pipelines.
Assign the roles/clouddeploy.viewer IAM role and query Cloud Audit Logs filtered by the clouddeploy.deliveryPipelines.listEffectiveTags API method.
Grant the roles/datafusion.viewer role to export Cloud Data Fusion execution metrics and query the datafusion.pipelines.get audit trail in Cloud Logging.
Enable Cloud Service Mesh authorization policies and query the server-accesslog-stackdriver log stream in Cloud Logging to extract deployment manifest headers.