ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 132 - Professional Cloud Security Engineer discussion

Report
Export

You are tasked with exporting and auditing security logs for login activity events for Google Cloud console and API calls that modify configurations to Google Cloud resources. Your export must meet the following requirements:

Export related logs for all projects in the Google Cloud organization.

Export logs in near real-time to an external SIEM.

What should you do? (Choose two.)

A.
Create a Log Sink at the organization level with a Pub/Sub destination.
Answers
A.
Create a Log Sink at the organization level with a Pub/Sub destination.
B.
Create a Log Sink at the organization level with the includeChildren parameter, and set the destination to a Pub/Sub topic.
Answers
B.
Create a Log Sink at the organization level with the includeChildren parameter, and set the destination to a Pub/Sub topic.
C.
Enable Data Access audit logs at the organization level to apply to all projects.
Answers
C.
Enable Data Access audit logs at the organization level to apply to all projects.
D.
Enable Google Workspace audit logs to be shared with Google Cloud in the Admin Console.
Answers
D.
Enable Google Workspace audit logs to be shared with Google Cloud in the Admin Console.
E.
Ensure that the SIEM processes the AuthenticationInfo field in the audit log entry to gather identity information.
Answers
E.
Ensure that the SIEM processes the AuthenticationInfo field in the audit log entry to gather identity information.
Suggested answer: B, D

Explanation:

'Google Workspace Login Audit: Login Audit logs track user sign-ins to your domain. These logs only record the login event. They don't record which system was used to perform the login action.' https://cloud.google.com/logging/docs/audit/gsuite-audit-logging#services

asked 18/09/2024
Thijs van Ham
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first