Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 448 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 448

Select 2Google Cloud Platform

Your company has recently implemented Google Cloud services and wants to ensure that all access to sensitive data is logged for compliance purposes. You are tasked with configuring Google Cloud Audit Logs to monitor data access events for Cloud Storage buckets. However, you notice that data access logs are not being generated by default. What steps must you take to enable and analyze these logs?

  1. A

    Enable Data Access audit logs for Cloud Storage in the Admin Activity Logs section of the Google Cloud Console.

  2. B

    Grant the appropriate IAM role, such as 'Logs Viewer', to the account analyzing the logs.

  3. C

    Explicitly enable Data Access audit logs for Cloud Storage at the project or organization level.

  4. D

    Use Cloud Monitoring to configure an alert for unauthorized access attempts logged in Data Access logs.

  5. E

    Verify that the required permissions, such as 'roles/logging.configWriter', are granted to enable audit log configurations.

Show answer and explanation

Correct answers: B, C

Explanation

To configure and analyze Google Cloud Audit Logs effectively, you must explicitly enable Data Access audit logs for services like Cloud Storage, as they are not enabled by default. Additionally, to analyze logs, the appropriate IAM permissions (e.g., 'Logs Viewer') must be granted to the account accessing the logs. Other options provided either reference unrelated actions or are not required for the specific scenario.

  • A. Incorrect.

    Incorrect. Data Access audit logs must be explicitly enabled, but they are not configured in the Admin Activity Logs section. Admin Activity Logs are always enabled and pertain to administrative actions, not data access.

  • B. Correct.

    Correct. To analyze logs, the account must have the correct IAM role, such as 'Logs Viewer', to view and query logs in Cloud Logging.

  • C. Correct.

    Correct. Data Access audit logs are not enabled by default and must be explicitly enabled at the project or organization level for Cloud Storage.

  • D. Incorrect.

    Incorrect. While Cloud Monitoring can help detect and alert on log events, it is not required for enabling Data Access audit logs.

  • E. Incorrect.

    Incorrect. While 'roles/logging.configWriter' allows configuration of logging settings, it is unrelated to enabling Data Access logs. Enabling logs is done via specific audit logging settings.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam