Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 447 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 447

Select 2Google Cloud Platform

Your organization is required to forward Google Cloud logs to an external SIEM (Security Information and Event Management) system for advanced threat detection and analysis. You need to design a solution to export these logs while ensuring scalability, security, and reliability. Which of the following steps should you take to achieve this?

  1. A

    Create a Logging sink in Google Cloud to export logs to a Cloud Storage bucket, and configure the SIEM to pull logs from the bucket.

  2. B

    Set up a Logging sink to send logs directly to the external SIEM by specifying the SIEM's endpoint URL.

  3. C

    Export logs to Google Pub/Sub using a Logging sink, and configure a Pub/Sub subscription to forward logs to the SIEM.

  4. D

    Encrypt logs using Cloud Key Management Service (KMS) before exporting them.

  5. E

    Use VPC Service Controls to restrict access to the logs during export to the SIEM.

Show answer and explanation

Correct answers: A, C

Explanation

Exporting logs to a Cloud Storage bucket or to Pub/Sub are both valid approaches for integrating with an external SIEM. Using a Logging sink provides a scalable and reliable way to route logs, and both Cloud Storage and Pub/Sub allow for secure and efficient integration with external systems. Direct log export to an external SIEM endpoint is not supported, and additional encryption steps are unnecessary because Google Cloud already ensures encryption of log data.

  • A. Correct.

    This is a valid solution. Exporting logs to a Cloud Storage bucket and configuring the SIEM to pull logs from the bucket is a common and scalable approach for log export.

  • B. Incorrect.

    This is incorrect because Logging sinks cannot directly send logs to external systems like SIEMs. Instead, logs must be routed through other Google Cloud services such as Cloud Storage or Pub/Sub.

  • C. Correct.

    This is a valid solution. Exporting logs to Pub/Sub and then configuring a subscription to forward logs to the SIEM is a reliable and scalable method for log export.

  • D. Incorrect.

    This is incorrect because while encryption is important, Cloud Logging data is already encrypted at rest and during transit by default. Additional encryption steps are not required for exporting logs.

  • E. Incorrect.

    This is incorrect because VPC Service Controls are used to restrict access to Google Cloud services but are not directly related to log export processes or SIEM integration.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam