Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 459 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 459

Select 3Google Cloud Platform

Your organization wants to centralize all Google Cloud logs from multiple projects into a single Cloud Storage bucket in the 'logging-central' project for long-term retention. You also need to ensure that the configuration is scalable as new projects are added in the future. What steps should you take to achieve this goal?

  1. A

    Create an aggregated log sink in the 'logging-central' project targeting the Cloud Storage bucket.

  2. B

    Grant the 'roles/logging.admin' role to the Cloud Storage bucket's service account.

  3. C

    Ensure that the Cloud Storage bucket has the 'roles/storage.objectCreator' permission for the appropriate service account used by the log sink.

  4. D

    Enable the Cloud Logging API in all the projects that need to export logs.

  5. E

    Manually create a log sink in each project and configure it to send logs to the Cloud Storage bucket in the 'logging-central' project.

Show answer and explanation

Correct answers: A, C, D

Explanation

To centralize logs from multiple projects, you should configure an aggregated log sink in the 'logging-central' project that targets the desired Cloud Storage bucket. The service account used by the log sink must have the 'roles/storage.objectCreator' permission for the bucket to write logs. Additionally, the Cloud Logging API must be enabled in all projects to export logs. This approach ensures scalability and avoids the repetitive task of configuring individual sinks for each project.

  • A. Correct.

    Correct: Aggregated log sinks allow you to centralize logs from multiple projects, folders, or organizations. This is a scalable solution for centralizing logs.

  • B. Incorrect.

    Incorrect: Granting 'roles/logging.admin' to the Cloud Storage bucket's service account is unnecessary. Instead, permissions should focus on allowing the log sink to write to the bucket.

  • C. Correct.

    Correct: The service account used by the log sink requires the 'roles/storage.objectCreator' permission to write logs to the Cloud Storage bucket.

  • D. Correct.

    Correct: The Cloud Logging API must be enabled in all projects to allow logs to be exported via sinks.

  • E. Incorrect.

    Incorrect: Manually creating log sinks in each project is not scalable and contradicts the use of aggregated log sinks, which are designed for centralizing logs from multiple projects.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam