Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 443 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 443

Select 3Google Cloud Platform

Your organization uses Google Cloud and wants to integrate its audit logs with an external SIEM (Security Information and Event Management) system for advanced threat detection and compliance reporting. The SIEM supports ingestion of logs via Pub/Sub. What steps must you take to securely export logs to the external SIEM?

  1. A

    Create a sink in Cloud Logging to export logs to a Pub/Sub topic.

  2. B

    Configure a service account with Pub/Sub Publisher permissions to allow the SIEM to pull messages from the Pub/Sub topic.

  3. C

    Ensure that log entries are filtered in the sink to export only relevant logs to the SIEM.

  4. D

    Enable VPC Service Controls on the Pub/Sub topic to restrict access to the SIEM.

  5. E

    Set up the SIEM to subscribe to the Pub/Sub topic and process the logs.

Show answer and explanation

Correct answers: A, C, E

Explanation

To securely export logs to an external SIEM using Pub/Sub, you need to create a Cloud Logging sink to route logs to a Pub/Sub topic. Filtering logs at the sink ensures only relevant data is sent to the SIEM, which helps with cost and compliance. Finally, the SIEM must subscribe to the Pub/Sub topic to ingest the logs. Ensuring proper IAM permissions for the Pub/Sub topic is crucial for secure access, but configuring a service account for Pub/Sub Publisher permissions or enabling VPC Service Controls is unnecessary in this scenario.

  • A. Correct.

    Correct: Creating a sink in Cloud Logging is necessary to export logs to a Pub/Sub topic, which can then be used by the external SIEM.

  • B. Incorrect.

    Incorrect: The SIEM typically subscribes to the Pub/Sub topic directly, so this step is unnecessary. Instead, ensure the topic permissions are correctly configured.

  • C. Correct.

    Correct: Filtering logs in the sink ensures that only relevant logs are forwarded to the external SIEM, reducing noise and costs.

  • D. Incorrect.

    Incorrect: VPC Service Controls are not typically applied to Pub/Sub for log exports. Instead, you control access using IAM permissions.

  • E. Correct.

    Correct: The SIEM must subscribe to the Pub/Sub topic to retrieve and process the exported logs.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam