Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
A financial enterprise is designing a centralized logging and compliance architecture across all Google Cloud projects in its organization. The compliance and security teams have established the following requirements:
Which logging and storage strategy should the enterprise implement to satisfy these requirements?
This solution implements an enterprise-grade log retention, archival, and access control architecture by combining aggregated Cloud Logging sinks, Cloud Storage Object Lifecycle Management, Cloud Storage Bucket Lock, and granular Identity and Access Management (IAM) roles.
SetStorageClass action automatically inspects object age conditions and transitions data from Standard storage to Coldline storage after 90 days, significantly reducing long-term storage expenditures for infrequently accessed audit records.roles/storage.objectViewer gives auditors read-only access to inspect log objects while strictly withholding write, delete, and policy modification privileges (storage.buckets.setIamPolicy).Using Cloud Storage with Bucket Lock and Object Lifecycle Management provides a fully managed, compliant, and cost-effective long-term archival solution that exceeds the operational capabilities of standard log buckets while strictly enforcing least privilege.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.