Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 450 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 450

Single answerGoogle Cloud Platform

Your organization has recently enabled Google Cloud Audit Logs for all projects in your organization. However, your security team notices that they are not able to view logs for read operations on BigQuery datasets. How can you ensure that these logs are captured and available for analysis?

  1. A

    Enable the Data Access audit logs for BigQuery in the Google Cloud Console.

  2. B

    Grant the security team the 'Viewer' role on the BigQuery datasets.

  3. C

    Enable the 'Admin Activity' audit logs for BigQuery in the Google Cloud Console.

  4. D

    Set up a custom IAM role to grant the security team access to the Data Access logs.

Show answer and explanation

Correct answer: A

Explanation

To capture read operations on BigQuery datasets, you must enable Data Access audit logs. These logs are not enabled by default, unlike Admin Activity logs, and must be configured manually for specific services or resources in your Google Cloud environment. Once enabled, the necessary logs will be generated and can be analyzed by the security team.

  • A. Correct.

    Correct. Data Access audit logs are not enabled by default and must be explicitly enabled for specific services like BigQuery. This is required to capture read operations.

  • B. Incorrect.

    Incorrect. Granting the 'Viewer' role on the datasets only provides access to the data, not the audit logs.

  • C. Incorrect.

    Incorrect. Admin Activity audit logs capture administrative operations, not data read operations. These logs are enabled by default and do not fulfill the requirement in this scenario.

  • D. Incorrect.

    Incorrect. While creating a custom IAM role might be useful for managing access to logs, it does not enable the logging of read operations. Enabling Data Access logs is the necessary step.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam