Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
A security engineer needs to establish centralized detection and alerting across an enterprise Google Cloud organization for unauthorized API invocation attempts and policy violations blocked at the perimeter.
The solution must fulfill the following operational requirements:
Which configuration strategy should the engineer implement?
This architecture centralizes organization-wide Cloud Audit Logs into a dedicated security logging project, establishes custom logs-based metrics targeting specific policy violation streams, and triggers automated alerts via Cloud Monitoring.
cloudaudit.googleapis.com%2Factivity) and logs access blocks enforced by perimeter controls (such as VPC Service Controls and IAM) in Policy Denied logs (cloudaudit.googleapis.com%2Fpolicy).RequestMetadata.caller_ip), method names (protoPayload.methodName), and resource identities, facilitating precise metric filtering.Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.