Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 426 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 426

Select 3Google Cloud Platform

You are designing a logging strategy for an e-commerce application deployed on Google Cloud. The application handles sensitive customer data, and your goal is to ensure logs are comprehensive, secure, and compliant with regulatory requirements. Which of the following steps should you include in your logging strategy?

  1. A

    Enable Cloud Audit Logs to track administrative, data, and system activities.

  2. B

    Store all logs indefinitely in Cloud Storage to ensure long-term accessibility.

  3. C

    Implement log filtering to exclude sensitive data from being logged.

  4. D

    Use Cloud Logging sinks to export logs to a centralized logging repository.

  5. E

    Grant 'Owner' roles to developers for log access to simplify troubleshooting.

Show answer and explanation

Correct answers: A, C, D

Explanation

Designing an effective logging strategy involves enabling Cloud Audit Logs to ensure visibility into activities, implementing log filtering to prevent sensitive data exposure, and using centralized logging repositories for better log management. Storing logs indefinitely and granting overly broad permissions do not align with security best practices or compliance requirements.

  • A. Correct.

    Enabling Cloud Audit Logs is essential for tracking administrative, data access, and system activities. This provides visibility into system operations and helps ensure compliance with regulatory requirements.

  • B. Incorrect.

    Storing all logs indefinitely without considering retention policies or regulatory requirements is not recommended. Logs should have a defined retention period based on compliance and operational needs.

  • C. Correct.

    Implementing log filtering is a best practice to ensure sensitive data, such as PII or credentials, is not logged. This step aligns with security and compliance requirements.

  • D. Correct.

    Using Cloud Logging sinks to export logs to a centralized repository helps in managing and analyzing logs efficiently, especially in multi-project environments.

  • E. Incorrect.

    Granting 'Owner' roles to developers violates the principle of least privilege and could expose sensitive data unnecessarily. Instead, granular IAM roles should be used for log access.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam