Professional Cloud DevOps Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise running high-throughput microservices on Google Kubernetes Engine (GKE) and Cloud Bigtable is experiencing high observability costs due to massive Cloud Logging volumes. The DevOps team must optimize logging costs according to FinOps best practices while satisfying the following architectural requirements:
DATA_READ and DATA_WRITE audit logs generated by trusted backend service accounts from creating cost overhead./healthz) and informational debug logs while preserving critical error and security logs in Cloud Logging for 30-day operational triage.Which logging architecture strategy should the DevOps team implement?
Create a custom user-defined log bucket configured with a 2,555-day retention period, route all logs using an aggregated sink, and apply field-level access control to redact debug and health check payloads.
Exempt backend service accounts via IAM Data Access audit configurations, add exclusion filters for debug and health check logs on the _Default log sink, and route compliance logs via a custom sink to a Cloud Storage bucket configured with Object Lifecycle Management.
Disable the _Default log sink entirely, route all unparsed logs into BigQuery via a continuous streaming sink, and configure BigQuery scheduled queries to drop debug rows every 24 hours.
Add exclusion filters to the _Required log sink to drop Data Access logs, and deploy a Cloud Run job that executes daily to delete expired debug entries from the _Default log bucket.
Create a custom user-defined log bucket configured with a 2,555-day retention period, route all logs using an aggregated sink, and apply field-level access control to redact debug and health check payloads.
Exempt backend service accounts via IAM Data Access audit configurations, add exclusion filters for debug and health check logs on the _Default log sink, and route compliance logs via a custom sink to a Cloud Storage bucket configured with Object Lifecycle Management.
This solution implements a multi-tier log optimization architecture that controls log volume at generation, ingestion, and retention tiers by combining IAM Audit Configuration exemptions, Log Router exclusion filters, and Cloud Storage log sinks.
DATA_READ and DATA_WRITE logs from being generated at the source. This completely eliminates the API and processing load before log entry creation._Default sink drops routine /healthz and verbose debug logs before they are written to the _Default log bucket. Cloud Logging only charges for logs stored in log buckets (beyond the free tier); excluded logs incur no storage charges while allowing critical errors to flow through for standard 30-day operational triage.This architecture manages costs at every stage of the log lifecycle: generation (IAM exemptions), ingestion/storage (sink exclusions), and retention (Cloud Storage lifecycle policies). It maintains required operational and compliance visibility at the lowest possible cost.
Disable the _Default log sink entirely, route all unparsed logs into BigQuery via a continuous streaming sink, and configure BigQuery scheduled queries to drop debug rows every 24 hours.
Add exclusion filters to the _Required log sink to drop Data Access logs, and deploy a Cloud Run job that executes daily to delete expired debug entries from the _Default log bucket.