Professional Cloud DevOps Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An organization is running containerized microservices where application logs occasionally contain sensitive user data, such as jsonPayload.user_email and jsonPayload.tax_id.
DevOps engineers require continuous access to these logs in Logs Explorer to debug production incidents, inspect error codes, and verify request latency. However, security compliance requires that standard engineers cannot view the sensitive PII fields, while authorized compliance auditors must retain the ability to inspect the full, unredacted log entries.
Which native Cloud Logging strategy should you implement to meet these requirements?
Define an exclusion filter on the _Default log sink matching jsonPayload.user_email:* OR jsonPayload.tax_id:* so that sensitive fields are stripped before ingestion.
Configure field-level access controls on the log bucket by setting the restricted fields list, and grant the roles/logging.fieldAccessor IAM role exclusively to the compliance auditors.
Create two separate Log Views on the log bucket, applying a filter on the engineers' Log View to hide log entries containing jsonPayload.user_email and jsonPayload.tax_id.
Enable Log Analytics on the bucket, configure field-level access controls, and use SQL views to mask the sensitive JSON payload keys.
Define an exclusion filter on the _Default log sink matching jsonPayload.user_email:* OR jsonPayload.tax_id:* so that sensitive fields are stripped before ingestion.
Configure field-level access controls on the log bucket by setting the restricted fields list, and grant the roles/logging.fieldAccessor IAM role exclusively to the compliance auditors.
Field-level access control in Cloud Logging allows administrators to restrict access to specific leaf fields or nested paths within a LogEntry (such as specific fields inside jsonPayload, httpRequest, or labels) at the log bucket level without dropping or hiding the entire log message.
LogEntry in Logs Explorer to inspect metadata, error traces, and operational context; the restricted leaf fields are simply redacted and omitted from their query results.jsonPayload.user_email,jsonPayload.tax_id in --restricted-fields, non-privileged users cannot view these values or query them directly.roles/logging.fieldAccessor (optionally scoped via IAM conditions) to compliance auditors allows them to view and search the complete, unredacted log entries when necessary.Alternative solutions like exclusion filters or log views drop or hide the entire log entry, making it impossible for DevOps teams to debug operational issues. Field-level access control specifically targets sensitive fields while leaving all other telemetry intact.
Create two separate Log Views on the log bucket, applying a filter on the engineers' Log View to hide log entries containing jsonPayload.user_email and jsonPayload.tax_id.
Enable Log Analytics on the bucket, configure field-level access controls, and use SQL views to mask the sensitive JSON payload keys.