Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A financial services organization must implement a centralized log export architecture across all Google Cloud resources to comply with strict regulatory frameworks. The compliance and security requirements are:
europe-west3).Which log export and IAM configuration should the security team implement?
Create an aggregated sink at the organization level with --include-children enabled, targeting a multi-region Cloud Storage bucket in a dedicated security project. Grant the sink's generated writer identity the roles/storage.objectAdmin role on the bucket.
Create an aggregated sink at the organization level with --include-children enabled, targeting a Cloud Storage bucket located in europe-west3 within a dedicated security project. Grant the sink's generated writer identity only the roles/storage.objectCreator role on the destination bucket.
Deploy individual project-level sinks in every project targeting a regional Cloud Storage bucket in europe-west3. Grant each project's default Compute Engine service account the roles/storage.objectCreator role on the bucket.
Create an aggregated sink at the organization level with --include-children disabled, targeting a BigQuery dataset in europe-west3. Grant the sink's generated writer identity the roles/bigquery.admin role on the destination dataset.
Create an aggregated sink at the organization level with --include-children enabled, targeting a multi-region Cloud Storage bucket in a dedicated security project. Grant the sink's generated writer identity the roles/storage.objectAdmin role on the bucket.
Create an aggregated sink at the organization level with --include-children enabled, targeting a Cloud Storage bucket located in europe-west3 within a dedicated security project. Grant the sink's generated writer identity only the roles/storage.objectCreator role on the destination bucket.
This solution uses a Google Cloud aggregated log sink at the organization level combined with least-privilege IAM permissions and regional Cloud Storage configuration to deliver a centralized, secure, and compliant log repository.
--include-children flag guarantees that all current and future child folders and projects automatically export their audit logs without requiring manual sink deployment per project.europe-west3 in a dedicated logging project guarantees that log archives remain stored within the mandated regulatory boundaries.roles/storage.objectCreator ensures write-only access—the writer identity can upload (storage.objects.create) new log objects but cannot read, overwrite, or delete existing log entries. Furthermore, centralizing storage in a restricted security project isolates logs from child project administrators.roles/storage.objectCreator role prevents log exfiltration (no read permissions) and log tampering (no overwrite or delete permissions).This architecture satisfies all compliance and isolation requirements by leveraging native GCP aggregated log sinks and atomic IAM role assignments, eliminating administrative overhead while enforcing strict data residency and write-only integrity.
Deploy individual project-level sinks in every project targeting a regional Cloud Storage bucket in europe-west3. Grant each project's default Compute Engine service account the roles/storage.objectCreator role on the bucket.
Create an aggregated sink at the organization level with --include-children disabled, targeting a BigQuery dataset in europe-west3. Grant the sink's generated writer identity the roles/bigquery.admin role on the destination dataset.