Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
A multinational financial enterprise requires a centralized, tamper-proof security logging architecture across its entire Google Cloud organization to satisfy strict regulatory compliance requirements.
The security engineering team defines the following mandatory requirements:
Which combination of actions should the security engineer implement?
This architecture establishes an organization-wide centralized logging pipeline that aggregates audit events, enforces data immutability, utilizes customer-controlled cryptography, and restricts access through granular log views.
--include-children setting automatically routes audit logs from all existing and future child folders and projects into the centralized logging project.logName : "cloudaudit.googleapis.com%2Factivity" and granting the roles/logging.viewAccessor IAM role allows compliance auditors to inspect administrative actions without accessing Data Access audit records.Native Cloud Logging features—specifically aggregated sinks, user-defined locked log buckets, and bucket log views—provide native end-to-end immutability, granular access scoping, and centralized query capabilities through Logs Explorer and Log Analytics without introducing third-party operational dependencies.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.