Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A multinational financial enterprise requires a centralized, tamper-proof security logging architecture across its entire Google Cloud organization to satisfy strict regulatory compliance requirements.
The security engineering team defines the following mandatory requirements:
Which combination of actions should the security engineer implement?
Create an organization-level aggregated sink routing to the _Required log bucket of the central security project, configure custom retention on the _Required bucket, and grant auditors the roles/logging.privateLogViewer role.
Create an organization-level aggregated sink routing to a Cloud Storage bucket with Object Lock enabled, configure CMEK on the bucket, and grant the auditors the Storage Object Viewer role.
Create an organization-level aggregated sink with children inclusion routing to a CMEK-encrypted user-defined log bucket in the security project, lock the log bucket, create a custom log view filtering out Data Access logs, and grant the auditors roles/logging.viewAccessor on that view.
Create project-level sinks in every project routing to the _Default log bucket in the central security project, configure customer-managed encryption keys on the _Default bucket, and grant auditors the roles/logging.viewer role on the central project.
Create an organization-level aggregated sink routing to the _Required log bucket of the central security project, configure custom retention on the _Required bucket, and grant auditors the roles/logging.privateLogViewer role.
Create an organization-level aggregated sink routing to a Cloud Storage bucket with Object Lock enabled, configure CMEK on the bucket, and grant the auditors the Storage Object Viewer role.
Create an organization-level aggregated sink with children inclusion routing to a CMEK-encrypted user-defined log bucket in the security project, lock the log bucket, create a custom log view filtering out Data Access logs, and grant the auditors roles/logging.viewAccessor on that view.
This architecture establishes an organization-wide centralized logging pipeline that aggregates audit events, enforces data immutability, utilizes customer-controlled cryptography, and restricts access through granular log views.
--include-children setting automatically routes audit logs from all existing and future child folders and projects into the centralized logging project.logName : "cloudaudit.googleapis.com%2Factivity" and granting the roles/logging.viewAccessor IAM role allows compliance auditors to inspect administrative actions without accessing Data Access audit records.Native Cloud Logging features—specifically aggregated sinks, user-defined locked log buckets, and bucket log views—provide native end-to-end immutability, granular access scoping, and centralized query capabilities through Logs Explorer and Log Analytics without introducing third-party operational dependencies.
Create project-level sinks in every project routing to the _Default log bucket in the central security project, configure customer-managed encryption keys on the _Default bucket, and grant auditors the roles/logging.viewer role on the central project.