Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise security operations team needs to centrally monitor and alert on potential credential-stuffing and unauthorized access attempts across 20 Google Cloud projects. The team has established the following operational requirements:
Which monitoring and alerting architecture should the security engineer implement?
Deploy the Ops Agent across all project workloads to collect audit logs, enable Cloud Logging exclusion filters to forward security entries, and create a single SQL-based alerting policy in Cloud Monitoring.
Configure user-defined counter log-based metrics extracting caller metadata from audit logs in each project, establish a multi-project metrics scope in a centralized scoping project, and create a metric-based alerting policy and custom dashboard in the scoping project.
Create distribution log-based metrics for audit logs in each project, export metrics to Cloud Monitoring synthetic monitors using Pub/Sub sinks, and deploy predefined integrations dashboards.
Configure direct log-based alerting policies in a central project using an aggregated log sink, and build a Cloud Monitoring custom dashboard configured to track open incidents from those policies.
Deploy the Ops Agent across all project workloads to collect audit logs, enable Cloud Logging exclusion filters to forward security entries, and create a single SQL-based alerting policy in Cloud Monitoring.
Configure user-defined counter log-based metrics extracting caller metadata from audit logs in each project, establish a multi-project metrics scope in a centralized scoping project, and create a metric-based alerting policy and custom dashboard in the scoping project.
This architecture combines user-defined counter log-based metrics with Cloud Monitoring metrics scopes to enable centralized, multi-project security observability and automated threshold alerting over Cloud Audit Logs.
severity>=ERROR or specific gRPC/HTTP status codes) as they are ingested by Cloud Logging.protoPayload.authenticationInfo.principalEmail and protoPayload.serviceName), allowing Cloud Monitoring to record separate time series for each combination of label values.Metric-based alerting policies built on log-based metrics leverage the full aggregation, grouping, and cross-project scoping capabilities of Cloud Monitoring. In contrast, log-based alerting policies operate only within individual project boundaries and cannot leverage multi-project metrics scopes.
Create distribution log-based metrics for audit logs in each project, export metrics to Cloud Monitoring synthetic monitors using Pub/Sub sinks, and deploy predefined integrations dashboards.
Configure direct log-based alerting policies in a central project using an aggregated log sink, and build a Cloud Monitoring custom dashboard configured to track open incidents from those policies.