Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A financial services organization hosted on Google Cloud must comply with strict regulatory auditability and threat monitoring requirements across all existing and future projects in its resource hierarchy. The compliance and security teams mandate the following requirements:
DATA_READ, DATA_WRITE, and ADMIN_READ) across all services.Which architecture should the security engineer implement to satisfy these compliance and monitoring requirements?
Enable Cloud Audit Logs at the folder level; create non-aggregated sinks routing to Cloud Logging storage buckets; set retention to 2,555 days; and configure IAM Deny policies preventing the logging.buckets.delete permission for all users and service accounts.
Deploy Cloud Service Mesh audit authorization policies across all clusters; configure a central Pub/Sub topic export sink; route events to Cloud Storage using Customer-Managed Encryption Keys (CMEK); and enable Cloud Audit Logs within Google Security Operations SIEM feeds.
Enable Data Access audit logs for all services in the Organization's default IAM audit configuration; configure an aggregated log sink at the Organization level with includeChildren=true targeting a dedicated Cloud Storage bucket; enforce a 7-year retention policy locked with Bucket Lock; and enable Security Command Center with Event Threat Detection.
Configure Data Access audit logs within each individual project's IAM settings; create standard project-level Cloud Logging sinks exporting to a centralized BigQuery dataset; set a 7-year partition expiration policy; and deploy custom Cloud Functions to parse table rows for anomalous IAM role grants.
Enable Cloud Audit Logs at the folder level; create non-aggregated sinks routing to Cloud Logging storage buckets; set retention to 2,555 days; and configure IAM Deny policies preventing the logging.buckets.delete permission for all users and service accounts.
Deploy Cloud Service Mesh audit authorization policies across all clusters; configure a central Pub/Sub topic export sink; route events to Cloud Storage using Customer-Managed Encryption Keys (CMEK); and enable Cloud Audit Logs within Google Security Operations SIEM feeds.
Enable Data Access audit logs for all services in the Organization's default IAM audit configuration; configure an aggregated log sink at the Organization level with includeChildren=true targeting a dedicated Cloud Storage bucket; enforce a 7-year retention policy locked with Bucket Lock; and enable Security Command Center with Event Threat Detection.
This architecture establishes a centralized, organization-wide logging, immutable retention, and automated threat detection framework using Google Cloud native compliance controls.
DATA_READ, DATA_WRITE, and ADMIN_READ log types across all services and child resources. Admin Activity logs are enabled by default.includeChildren=true intercepts and routes all audit log entries from all current and future folders and projects into a centralized compliance destination.Alternative approaches that rely on project-level log exports or standard IAM ACLs introduce operational overhead, allow accidental gaps in new projects, and fail to guarantee true immutability against privileged administrative overrides.
Configure Data Access audit logs within each individual project's IAM settings; create standard project-level Cloud Logging sinks exporting to a centralized BigQuery dataset; set a 7-year partition expiration policy; and deploy custom Cloud Functions to parse table rows for anomalous IAM role grants.