Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 441 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 441

Select 3Google Cloud Platform

Your company wants to ensure secure access to Cloud Logging data while minimizing the risk of unauthorized access. Only designated administrators and auditors should have access to view logs, while developers should be restricted to access logs for a specific project. Which approach should you take to implement this requirement?

  1. A

    Use IAM roles such as 'roles/logging.admin' and 'roles/logging.viewer' to grant access based on user responsibilities.

  2. B

    Grant the 'roles/owner' role to developers so they can access logs for their project.

  3. C

    Restrict developers’ access to logs by applying custom IAM roles with permissions limited to specific log buckets.

  4. D

    Enable Audit Logs in Google Cloud to track all access and modifications to logs.

  5. E

    Use VPC Service Controls to define a service perimeter around Cloud Logging to prevent unauthorized data exfiltration.

Show answer and explanation

Correct answers: A, C, D

Explanation

To implement secure access to logs, it is essential to apply IAM roles to enforce access based on user responsibilities, use custom IAM roles for specific needs like restricting developer access, and enable Audit Logs to monitor access and modifications. This ensures a secure and compliant logging environment while adhering to the principle of least privilege. VPC Service Controls are not directly related to granting or restricting user-level log access.

  • A. Correct.

    Using predefined IAM roles such as 'roles/logging.admin' (for administrators) and 'roles/logging.viewer' (for auditors) is the recommended way to assign access based on responsibilities. This ensures secure and granular control over log access.

  • B. Incorrect.

    Granting the 'roles/owner' role to developers is not recommended as it provides full administrative access to the project, including permissions beyond log access, which violates the principle of least privilege.

  • C. Correct.

    Creating custom IAM roles with specific permissions for logs ensures developers only access logs for the specified projects or log buckets, adhering to security best practices.

  • D. Correct.

    Enabling Audit Logs provides visibility into who accessed or modified logs, which is crucial for compliance and security monitoring. However, it does not enforce access control by itself.

  • E. Incorrect.

    While VPC Service Controls enhance data security by defining a service perimeter, they are not directly used for managing user permissions to access logs. They focus on preventing data exfiltration rather than granular access control.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam