Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
A financial services organization must implement a centralized log export architecture across all Google Cloud resources to comply with strict regulatory frameworks. The compliance and security requirements are:
europe-west3).Which log export and IAM configuration should the security team implement?
This solution uses a Google Cloud aggregated log sink at the organization level combined with least-privilege IAM permissions and regional Cloud Storage configuration to deliver a centralized, secure, and compliant log repository.
--include-children flag guarantees that all current and future child folders and projects automatically export their audit logs without requiring manual sink deployment per project.europe-west3 in a dedicated logging project guarantees that log archives remain stored within the mandated regulatory boundaries.roles/storage.objectCreator ensures write-only access—the writer identity can upload (storage.objects.create) new log objects but cannot read, overwrite, or delete existing log entries. Furthermore, centralizing storage in a restricted security project isolates logs from child project administrators.roles/storage.objectCreator role prevents log exfiltration (no read permissions) and log tampering (no overwrite or delete permissions).This architecture satisfies all compliance and isolation requirements by leveraging native GCP aggregated log sinks and atomic IAM role assignments, eliminating administrative overhead while enforcing strict data residency and write-only integrity.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.