Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 436 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 436

Select 3Google Cloud Platform

Your organization uses Google Cloud Logging to collect and manage logs from various GCP services. You need to ensure that access to logs is secure and restricted to only authorized personnel while maintaining compliance with organizational policies. Which of the following steps should you take to design secure access to logs?

  1. A

    Use Identity and Access Management (IAM) roles such as 'Logs Viewer' or 'Logs Admin' to assign permissions.

  2. B

    Grant 'Owner' role at the project level to ensure comprehensive access to logs for all users.

  3. C

    Enable audit logging for GCP services to monitor access to logs.

  4. D

    Restrict access to logs by using custom IAM roles with the least privilege principle.

  5. E

    Store logs in a publicly accessible Cloud Storage bucket for transparency.

Show answer and explanation

Correct answers: A, C, D

Explanation

To design secure access to logs in Google Cloud, it is essential to use IAM roles (predefined or custom) to grant appropriate permissions while adhering to the principle of least privilege. Audit logging should be enabled to monitor and track access to logs for compliance. Avoid assigning overly broad roles like 'Owner' or exposing logs publicly, as this increases the risk of unauthorized access and data breaches.

  • A. Correct.

    Correct. Using predefined IAM roles like 'Logs Viewer' or 'Logs Admin' ensures permissions are assigned appropriately based on the user's role and responsibilities.

  • B. Incorrect.

    Incorrect. Granting 'Owner' role at the project level violates the principle of least privilege, as it provides excessive access to all resources, not just logs.

  • C. Correct.

    Correct. Enabling audit logging helps track access to logs, providing visibility and ensuring compliance with organizational policies.

  • D. Correct.

    Correct. Custom IAM roles with the least privilege principle ensure that users have only the permissions they need to perform specific tasks, minimizing the risk of unauthorized access.

  • E. Incorrect.

    Incorrect. Storing logs in a publicly accessible Cloud Storage bucket compromises security and violates best practices for securing access to logs.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam