Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 449 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 449

Select 3Google Cloud Platform

Your organization uses Google Cloud for hosting sensitive applications and has a compliance requirement to track all read and write access to Cloud Storage buckets. You have been tasked with ensuring that audit logs, including Data Access logs, are properly configured and monitored. What steps should you take to meet this requirement?

  1. A

    Enable Data Access logs for all services in your organization using the Google Cloud Console.

  2. B

    Ensure that the IAM policy grants the 'roles/logging.admin' role to a service account that will manage the logs.

  3. C

    Configure a Logging Sink to export audit logs to a secure Cloud Storage bucket for long-term retention.

  4. D

    Enable Data Access logs for Cloud Storage at the organizational level through gcloud CLI or Resource Manager API.

  5. E

    Use Cloud Monitoring to configure alerts for any missing Data Access logs or anomalies in log events.

Show answer and explanation

Correct answers: C, D, E

Explanation

To meet the compliance requirement of tracking all read and write access to Cloud Storage buckets, you must enable Data Access logs for Cloud Storage resources, as they are disabled by default. Additionally, configuring a Logging Sink ensures that these logs are securely stored for long-term retention. Using Cloud Monitoring to detect missing logs or anomalies adds an extra layer of monitoring to meet compliance and security needs. While roles like 'roles/logging.admin' are useful for managing logs, they are not directly tied to enabling or configuring audit logs.

  • A. Incorrect.

    This option is incorrect because Data Access logs are disabled by default and must be enabled explicitly for specific services or resources. There is no option to enable Data Access logs for all services in the Google Cloud Console.

  • B. Incorrect.

    This option is incorrect because while IAM roles like 'roles/logging.admin' are useful for managing logs, this step is not directly related to enabling or configuring Data Access logs.

  • C. Correct.

    This option is correct. Configuring a Logging Sink to export audit logs to a secure location, such as a Cloud Storage bucket, ensures long-term retention and compliance with audit requirements.

  • D. Correct.

    This option is correct. Data Access logs must be explicitly enabled for Cloud Storage at the organization, folder, or project level using gcloud CLI or the Resource Manager API, as they are not enabled by default.

  • E. Correct.

    This option is correct. Configuring Cloud Monitoring with alerts for missing logs or anomalies ensures proactive monitoring and compliance, especially for sensitive applications.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam