Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 432 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 432

Select 2Google Cloud Platform

Your organization runs a multi-project architecture in Google Cloud. You have been tasked with setting up a logging and monitoring solution for security incident detection and response. The primary goals are to centralize logs from all projects, ensure logs are retained for compliance, and enable automated alerting for suspicious activities. Which combination of actions should you take to meet these requirements?

  1. A

    Enable Cloud Logging and configure log sinks to export logs to a centralized, dedicated logging project.

  2. B

    Use Cloud Pub/Sub to stream logs in real-time to an external SIEM for analysis.

  3. C

    Set up Google Cloud Monitoring with custom alerting policies to detect specific security anomalies.

  4. D

    Use the Google Cloud Security Command Center (SCC) Premium tier to centralize and visualize logs across all projects.

  5. E

    Configure log retention at the default 30 days to reduce storage costs while meeting compliance requirements.

Show answer and explanation

Correct answers: A, C

Explanation

To meet the requirements of centralizing logs, ensuring compliance, and enabling alerting, enabling Cloud Logging with log sinks for centralization and using Google Cloud Monitoring with custom alerting policies are the most appropriate options. These solutions are native to Google Cloud, directly address the goals, and allow for scalability and automation. The other options, while useful in specific scenarios, are either not directly relevant to the stated goals or do not utilize native tools effectively.

  • A. Correct.

    Correct: Enabling Cloud Logging and configuring log sinks to export logs to a centralized project allows for centralization and easier management of logs across multiple projects.

  • B. Incorrect.

    Incorrect: While using Cloud Pub/Sub to stream logs to an external SIEM can be beneficial, the question focuses on native Google Cloud tools. This is an optional step but not required to meet the goals stated.

  • C. Correct.

    Correct: Google Cloud Monitoring with custom alerting policies enables the detection of specific security anomalies and supports automated alerting for suspicious activities.

  • D. Incorrect.

    Incorrect: While the Security Command Center Premium tier provides valuable security insights, it does not centralize raw logs or handle compliance-related log retention.

  • E. Incorrect.

    Incorrect: Configuring log retention at the default 30 days may conflict with compliance requirements, which often demand longer retention periods.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam