Professional Cloud DevOps Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
Your enterprise organization centralizes logs from multiple application projects into a dedicated centralized logging project. Your compliance and operations teams have established the following access control requirements for multi-project observability:
LogEntry payloads.Which solution should you implement to meet these requirements?
Configure a central log sink with exclusion filters that drops all payload fields containing email addresses before ingesting them into the log bucket, and assign the Logs Viewer role to all teams.
Create two separate log views on the centralized log bucket: one with an inclusion filter that omits PII and another with no filter. Assign developers access to the filtered log view and assign security analysts access to the unfiltered log view.
Grant developers the Private Logs Viewer role in the development projects, and grant security analysts the Logs Admin role on the centralized logging project.
Configure field-level access controls on the centralized log bucket to restrict the sensitive PII payload fields, grant developers the Logs Viewer role without field access permissions, and grant security analysts the Logs Viewer role along with the Field Accessor role.
Configure a central log sink with exclusion filters that drops all payload fields containing email addresses before ingesting them into the log bucket, and assign the Logs Viewer role to all teams.
Create two separate log views on the centralized log bucket: one with an inclusion filter that omits PII and another with no filter. Assign developers access to the filtered log view and assign security analysts access to the unfiltered log view.
Grant developers the Private Logs Viewer role in the development projects, and grant security analysts the Logs Admin role on the centralized logging project.
Configure field-level access controls on the centralized log bucket to restrict the sensitive PII payload fields, grant developers the Logs Viewer role without field access permissions, and grant security analysts the Logs Viewer role along with the Field Accessor role.
Field-level access control in Cloud Logging provides granular security by allowing administrators to restrict access to specific fields inside a LogEntry (such as jsonPayload.email or jsonPayload.ssn) while keeping the rest of the log record visible. Users without specific permissions can view the log entry, but restricted fields are masked or hidden.
roles/logging.viewer) ensures they can query, filter, and view application logs for debugging while automatically hiding sensitive PII fields.roles/logging.fieldAccessor role in addition to roles/logging.viewer gives them full clearance to read both unrestricted and restricted fields across the entire centralized repository.Field-level access control operates natively within the Cloud Logging platform. Compared to managing multiple log sinks or restricting access purely by entire log views, field-level controls enforce least privilege at the field level without complicating data routing topologies.