ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 155 - Associate Cloud Engineer discussion

Report
Export

You are storing sensitive information in a Cloud Storage bucket. For legal reasons, you need to be able to record all requests that read any of the stored dat

A.
You want to make sure you comply with these requirements. What should you do?
Answers
A.
You want to make sure you comply with these requirements. What should you do?
B.
Enable the Identity Aware Proxy API on the project.
Answers
B.
Enable the Identity Aware Proxy API on the project.
C.
Scan the bucker using the Data Loss Prevention API.
Answers
C.
Scan the bucker using the Data Loss Prevention API.
D.
Allow only a single Service Account access to read the data.
Answers
D.
Allow only a single Service Account access to read the data.
E.
Enable Data Access audit logs for the Cloud Storage API.
Answers
E.
Enable Data Access audit logs for the Cloud Storage API.
Suggested answer: D

Explanation:

Logged information Within Cloud Audit Logs, there are two types of logs: Admin Activity logs: Entries for operations that modify the configuration or metadata of a project, bucket, or object. Data Access logs: Entries for operations that modify objects or read a project, bucket, or object. There are several sub-types of data access logs: ADMIN_READ: Entries for operations that read the configuration or metadata of a project, bucket, or object. DATA_READ: Entries for operations that read an object. DATA_WRITE: Entries for operations that create or modify an object. https://cloud.google.com/storage/docs/audit-logs#types

asked 18/09/2024
Michel van Klaveren
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first