Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 424 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 424

Select 3Google Cloud Platform

Your organization has a multi-project Google Cloud environment and wants to implement a centralized logging strategy to monitor security events across all projects. The logging strategy must ensure that logs are retained for compliance purposes and allow security teams to query logs efficiently. What steps should you take to design this logging strategy?

  1. A

    Enable Cloud Logging in each project and configure log sinks to export logs to a centralized Cloud Storage bucket.

  2. B

    Use aggregated sinks to export logs from all projects to a centralized Cloud Logging bucket in a dedicated monitoring project.

  3. C

    Set up log retention policies in Cloud Logging to meet compliance requirements, ensuring that logs are not deleted prematurely.

  4. D

    Grant the security team the 'Owner' role on all projects to access logs efficiently.

  5. E

    Use BigQuery as a logging export destination to enable scalable querying of logs for security analysis.

Show answer and explanation

Correct answers: B, C, E

Explanation

To design an effective logging strategy for a multi-project environment, you should use aggregated sinks to centralize logs in a dedicated monitoring project. This simplifies management and monitoring. Retention policies should be configured to meet compliance requirements. Additionally, exporting logs to BigQuery allows for scalable querying and analysis, which is essential for security teams. Avoid granting overly permissive roles and ensure all configurations align with the principle of least privilege.

  • A. Incorrect.

    Exporting logs to a Cloud Storage bucket can be used for long-term archival, but it does not support efficient querying or centralized real-time analysis. This option does not fully meet the requirements.

  • B. Correct.

    Using aggregated sinks to export logs to a centralized Cloud Logging bucket is the recommended approach for centralizing logs from multiple projects and ensuring efficient monitoring.

  • C. Correct.

    Setting up log retention policies ensures compliance and prevents logs from being prematurely deleted, making this an essential aspect of the logging strategy.

  • D. Incorrect.

    Granting the 'Owner' role is not a best practice because it violates the principle of least privilege. Access to logs should be granted using specific roles such as 'Logs Viewer' or custom roles.

  • E. Correct.

    BigQuery is an excellent choice for exporting logs when scalable querying and advanced analysis are required, making it suitable for security use cases.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam