Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 417 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 417

Select 4Google Cloud Platform

Your organization has recently deployed multiple applications on Google Cloud. To meet compliance requirements, all API activities in Google Cloud must be monitored, and unauthorized access attempts should be detected in real-time. Which steps should you take to configure logging, monitoring, and detection effectively in this scenario?

  1. A

    Enable Cloud Audit Logs for all services and ensure ADMIN_READ and DATA_WRITE logs are captured.

  2. B

    Set up a Cloud Logging sink to export logs to a BigQuery dataset for further analysis.

  3. C

    Use Cloud Monitoring alert policies to create notifications for unauthorized access attempts.

  4. D

    Enable VPC Flow Logs and use them to detect API activity within your network.

  5. E

    Integrate Security Command Center to monitor and detect potential security threats in real-time.

Show answer and explanation

Correct answers: A, B, C, E

Explanation

To meet the compliance requirement of monitoring API activity and detecting unauthorized access in real-time, you need to enable Cloud Audit Logs to capture API activity, export logs to BigQuery for analysis, configure Cloud Monitoring alerts for unauthorized access, and use Security Command Center for real-time threat detection. VPC Flow Logs, while useful for network monitoring, do not directly address API activity or access monitoring.

  • A. Correct.

    Enabling Cloud Audit Logs is critical for tracking API activity and ensuring compliance. ADMIN_READ and DATA_WRITE logs capture administrative and data access operations, which are key for monitoring access attempts.

  • B. Correct.

    Exporting logs to BigQuery allows for detailed analysis and long-term storage, which is useful for compliance and detecting patterns of unauthorized access.

  • C. Correct.

    Cloud Monitoring alert policies can notify administrators in real-time about unauthorized access attempts, ensuring a prompt response.

  • D. Incorrect.

    While VPC Flow Logs are useful for monitoring network traffic, they do not directly help with tracking API activity or detecting unauthorized access to APIs.

  • E. Correct.

    Security Command Center provides a comprehensive view of potential security risks, including unauthorized access attempts, and is crucial for real-time threat detection.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam