Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
A financial services organization hosted on Google Cloud must comply with strict regulatory auditability and threat monitoring requirements across all existing and future projects in its resource hierarchy. The compliance and security teams mandate the following requirements:
DATA_READ, DATA_WRITE, and ADMIN_READ) across all services.Which architecture should the security engineer implement to satisfy these compliance and monitoring requirements?
This architecture establishes a centralized, organization-wide logging, immutable retention, and automated threat detection framework using Google Cloud native compliance controls.
DATA_READ, DATA_WRITE, and ADMIN_READ log types across all services and child resources. Admin Activity logs are enabled by default.includeChildren=true intercepts and routes all audit log entries from all current and future folders and projects into a centralized compliance destination.Alternative approaches that rely on project-level log exports or standard IAM ACLs introduce operational overhead, allow accidental gaps in new projects, and fail to guarantee true immutability against privileged administrative overrides.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.