Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
A security engineer is designing an enterprise-wide audit logging architecture across a Google Cloud Organization. The design must satisfy the following technical and operational requirements:
Which logging architecture should the engineer implement?
This solution implements an enterprise-grade log routing architecture using Google Cloud aggregated sinks, supported export destinations (Pub/Sub and BigQuery), and Log Router exclusions to capture critical audit telemetry while controlling storage and ingestion costs.
LogEntry records directly into standard BigQuery datasets for complex joins with enterprise data._Default sinks prevents high-volume Data Access logs from being ingested into local project _Default log buckets, eliminating unnecessary ingestion charges. Furthermore, mandatory Admin Activity logs are automatically routed and retained in the _Required bucket and cannot be dropped or excluded._Required bucket regardless of custom exclusion rules._Default sink level prevents runaway storage and ingestion costs.This architecture directly addresses the unique capabilities and constraints of Cloud Logging routing destinations. It uses Pub/Sub for real-time third-party streaming, avoids read-only BigQuery destination failures, and leverages built-in exclusion mechanisms to balance compliance visibility with cost governance.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.