Professional Cloud DevOps Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A DevOps team manages multi-project CI/CD pipelines and infrastructure deployments across an enterprise Google Cloud organization. To meet strict regulatory compliance and security auditing standards, the team must implement a centralized deployment auditing strategy that satisfies the following requirements:
Which combination of Cloud Audit Logs configuration and log routing should the DevOps engineer implement?
Rely on default Cloud Logging configurations, grant security analysts the Logs Viewer role (roles/logging.viewer), and route logs to a Cloud Storage coldline bucket via Pub/Sub topics.
Create non-aggregated project log sinks that exclude Data Access logs, configure Cloud Monitoring log-based metrics for all deployments, and query the logs using the Cloud Billing console.
Explicitly enable Admin Activity audit logs in the organization IAM policy, and configure individual project-level log sinks routing System Event audit logs to Cloud Storage buckets.
Explicitly enable Data Access audit logs for required services in the organization audit configuration, and create an organization-level aggregated log sink filtering for Cloud Audit Logs routed to a centralized BigQuery dataset.
Rely on default Cloud Logging configurations, grant security analysts the Logs Viewer role (roles/logging.viewer), and route logs to a Cloud Storage coldline bucket via Pub/Sub topics.
Create non-aggregated project log sinks that exclude Data Access logs, configure Cloud Monitoring log-based metrics for all deployments, and query the logs using the Cloud Billing console.
Explicitly enable Admin Activity audit logs in the organization IAM policy, and configure individual project-level log sinks routing System Event audit logs to Cloud Storage buckets.
Explicitly enable Data Access audit logs for required services in the organization audit configuration, and create an organization-level aggregated log sink filtering for Cloud Audit Logs routed to a centralized BigQuery dataset.
This architecture combines Google Cloud's Cloud Audit Logs configuration with an organization-level aggregated log sink destined for BigQuery.
k8s.io service) generate Data Access audit logs. Because Data Access audit logs are disabled by default (except for BigQuery), explicitly enabling them via the IAM audit policy at the organization or project level ensures these sensitive calls are recorded.cloudaudit.googleapis.com%2Factivity and cloudaudit.googleapis.com%2Fdata_access) to BigQuery allows security teams to retain logs long-term and execute high-performance analytical SQL queries across the enterprise dataset.ADMIN_READ, DATA_READ, and DATA_WRITE events that standard logging ignores.Aggregated sinks configured at the organization level eliminate operational overhead and security blind spots by capturing logs across all existing and new projects. Direct routing to BigQuery natively satisfies analytical SQL requirements without additional data transfer pipelines.