Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A security engineer needs to establish centralized detection and alerting across an enterprise Google Cloud organization for unauthorized API invocation attempts and policy violations blocked at the perimeter.
The solution must fulfill the following operational requirements:
Which configuration strategy should the engineer implement?
Configure an Istio AuthorizationPolicy with the AUDIT action inside Cloud Service Mesh on ingress gateways, and route the resulting envoy access logs directly to Cloud Monitoring using MQL alerting rules.
Aggregate organization-level Cloud Audit Logs for Admin Activity and Policy Denied logs (cloudaudit.googleapis.com%2Factivity and cloudaudit.googleapis.com%2Fpolicy) into a central project, create a logs-based metric filtered on policy denials and method calls, and attach a Cloud Monitoring alerting policy with notification channels.
Enable Data Access audit logs globally at the organization root, rely on the default _Default sink for storage in each individual project, and create project-level PromQL queries in Metrics Explorer to track cloudaudit.googleapis.com%2Fsystem_event.
Deploy the Google Cloud Ops Agent on all Compute Engine instances, configure a Prometheus endpoint to emit workload.googleapis.com metrics, and set up ActiveMQ integration alerting policies in Cloud Monitoring.
Configure an Istio AuthorizationPolicy with the AUDIT action inside Cloud Service Mesh on ingress gateways, and route the resulting envoy access logs directly to Cloud Monitoring using MQL alerting rules.
Aggregate organization-level Cloud Audit Logs for Admin Activity and Policy Denied logs (cloudaudit.googleapis.com%2Factivity and cloudaudit.googleapis.com%2Fpolicy) into a central project, create a logs-based metric filtered on policy denials and method calls, and attach a Cloud Monitoring alerting policy with notification channels.
This architecture centralizes organization-wide Cloud Audit Logs into a dedicated security logging project, establishes custom logs-based metrics targeting specific policy violation streams, and triggers automated alerts via Cloud Monitoring.
cloudaudit.googleapis.com%2Factivity) and logs access blocks enforced by perimeter controls (such as VPC Service Controls and IAM) in Policy Denied logs (cloudaudit.googleapis.com%2Fpolicy).RequestMetadata.caller_ip), method names (protoPayload.methodName), and resource identities, facilitating precise metric filtering.Enable Data Access audit logs globally at the organization root, rely on the default _Default sink for storage in each individual project, and create project-level PromQL queries in Metrics Explorer to track cloudaudit.googleapis.com%2Fsystem_event.
Deploy the Google Cloud Ops Agent on all Compute Engine instances, configure a Prometheus endpoint to emit workload.googleapis.com metrics, and set up ActiveMQ integration alerting policies in Cloud Monitoring.