Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 452 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 452

Select 3Google Cloud Platform

Your organization stores sensitive data in Google Cloud Storage buckets and has a requirement to monitor who accesses this data. You have been tasked with enabling logging to capture all read and write operations performed on the data, including any failed access attempts. What steps should you take to meet this requirement?

  1. A

    Enable Data Access audit logs for the required Google Cloud services in the appropriate Google Cloud project.

  2. B

    Grant the 'roles/logging.admin' role to all users who need to access the logs.

  3. C

    Ensure that the Cloud Storage bucket has Object Change Notification (OCN) enabled for logging.

  4. D

    Enable Cloud Audit Logs for all Admin Activity and Data Access logs for the project.

  5. E

    Configure a sink in Cloud Logging to export the logs to a secure destination, such as another Cloud Storage bucket.

Show answer and explanation

Correct answers: A, D, E

Explanation

To monitor access to sensitive data in Google Cloud Storage, you need to enable Data Access audit logs, which capture read and write activities. Additionally, enabling Cloud Audit Logs ensures that Admin Activity and Data Access logs are properly recorded. Configuring a sink allows you to securely export and store logs for further analysis or retention. Granting roles like 'logging.admin' or enabling Object Change Notification is not relevant to this scenario.

  • A. Correct.

    This is correct because enabling Data Access audit logs is necessary to capture read and write operations, which is required to monitor sensitive data access.

  • B. Incorrect.

    This is incorrect because granting the 'roles/logging.admin' role is not directly relevant to enabling or capturing the audit logs. This role is used for managing logging configurations.

  • C. Incorrect.

    This is incorrect because Object Change Notification (OCN) is unrelated to Cloud Audit Logs or Data Access logs. OCN is used for notifying changes in bucket objects, not for logging access details.

  • D. Correct.

    This is correct because enabling Cloud Audit Logs for Admin Activity and Data Access logs ensures that read/write operations and admin activities are logged.

  • E. Correct.

    This is correct because configuring a sink to export logs to a secure destination ensures that logs are stored securely and can be analyzed or retained as per compliance requirements.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam