Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 458 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 458

Select 3Google Cloud Platform

Your organization needs to export logs from multiple Google Cloud projects into a centralized logging bucket in a separate project for compliance purposes. You need to ensure that all logs from the projects are aggregated in real-time into the centralized bucket. Which of the following actions should you take to meet this requirement?

  1. A

    Create an aggregated sink in each source project and configure it to export logs to the centralized logging bucket.

  2. B

    Grant the necessary permissions to the centralized logging bucket to allow it to receive logs from the source projects.

  3. C

    Use the 'includeChildren' option when setting up the aggregated sink to include logs from all child resources of the source projects.

  4. D

    Create a sink in the centralized logging bucket to pull logs from the source projects.

  5. E

    Apply a filter to the aggregated sink to only include the required logs for export.

Show answer and explanation

Correct answers: B, C, E

Explanation

To aggregate logs from multiple projects into a centralized bucket, you need to create an aggregated sink at the organization or folder level with the 'includeChildren' option to capture all logs from the source projects and their child resources. The centralized bucket must have the appropriate permissions to receive logs, and applying a filter ensures that only the necessary logs are exported. This setup ensures efficient, real-time log aggregation into a single destination for compliance purposes.

  • A. Incorrect.

    This is incorrect. Aggregated sinks are created at the organization or folder level, not in each individual source project. Creating individual sinks in each project would not achieve centralized logging efficiently.

  • B. Correct.

    This is correct. The centralized logging bucket must have the appropriate permissions (e.g., roles/storage.objectAdmin) to allow it to receive logs from the source projects.

  • C. Correct.

    This is correct. The 'includeChildren' option ensures that logs from all child resources (e.g., projects, folders) of the specified organization or folder are included in the aggregated sink.

  • D. Incorrect.

    This is incorrect. Logs cannot be 'pulled' from source projects by a sink in the centralized logging bucket. Sinks push logs to the destination.

  • E. Correct.

    This is correct. Applying a filter to the aggregated sink allows you to streamline the logs being exported and ensures only relevant logs are sent to the centralized bucket.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam