Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam Professional Cloud Architect All Questions

View all questions & answers for the Professional Cloud Architect exam

Exam Professional Cloud Architect topic 1 question 28 discussion

Actual exam question from Google's Professional Cloud Architect
Question #: 28
Topic #: 1
[All Professional Cloud Architect Questions]

Auditors visit your teams every 12 months and ask to review all the Google Cloud Identity and Access Management (Cloud IAM) policy changes in the previous 12 months. You want to streamline and expedite the analysis and audit process.
What should you do?

  • A. Create custom Google Stackdriver alerts and send them to the auditor
  • B. Enable Logging export to Google BigQuery and use ACLs and views to scope the data shared with the auditor
  • C. Use cloud functions to transfer log entries to Google Cloud SQL and use ACLs and views to limit an auditor's view
  • D. Enable Google Cloud Storage (GCS) log export to audit logs into a GCS bucket and delegate access to the bucket
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
ghitesh
Highly Voted 4 years, 10 months ago
B. https://cloud.google.com/iam/docs/roles-audit-logging#scenario_external_auditors
upvoted 96 times
rockstar9622
4 years, 10 months ago
b) seems correct
upvoted 3 times
...
anton_royce
4 years, 7 months ago
I agree. Answer B
upvoted 5 times
...
MikeB19
3 years, 2 months ago
The article references either gcs or bq. I think this q is referring to gcs
upvoted 1 times
...
TheCloudBoy77
3 years ago
B makes more sense after reading it. thx
upvoted 4 times
...
...
jcmoranp
Highly Voted 5 years, 1 month ago
Think B is better. Export to Bigquery and restrict access to queries with ACLs to auditors
upvoted 37 times
trainor
3 years, 11 months ago
I think D is better. B implies too much data manipulation to make it suitable for an audit.
upvoted 4 times
...
tartar
4 years, 3 months ago
D is ok.
upvoted 7 times
tartar
4 years, 3 months ago
Sorry, changed my view. B is the recommended practice
upvoted 14 times
alii
3 years, 10 months ago
don't change your view, D was right :)
upvoted 4 times
RKS_2021
3 years, 4 months ago
B is correct
upvoted 1 times
...
...
...
...
nitinz
3 years, 8 months ago
D, rest all options are no good.
upvoted 3 times
AmitAr
2 years, 6 months ago
Please check the keywords in question -- "streamline and expedite" -- Bigquery is suitable not storage bucket. so it should be (B)
upvoted 3 times
...
...
passnow
4 years, 11 months ago
I thought same as well. I would go with B
upvoted 5 times
...
...
Ekramy_Elnaggar
Most Recent 1 week, 4 days ago
Selected Answer: B
1. Comprehensive Audit Trail: Cloud Logging automatically captures audit logs for all Cloud IAM activity. Exporting these logs to BigQuery provides a centralized and comprehensive audit trail for analysis. 2. Powerful Analysis: BigQuery's analytical capabilities allow auditors to efficiently query and analyze IAM policy changes over the 12-month period. They can filter, aggregate, and generate reports to identify any anomalies or security concerns. 3. Granular Access Control: BigQuery's Access Control Lists (ACLs) and views enable you to precisely control which data the auditors can access. This ensures that they only see the information relevant to their audit without exposing sensitive data. Note: While exporting logs to Cloud Storage is possible, it's less efficient for analysis compared to BigQuery.
upvoted 1 times
...
nareshthumma
4 weeks, 1 day ago
Answer B
upvoted 1 times
...
maxdanny
2 months, 2 weeks ago
Selected Answer: B
Option B is the best approach. Enable Logging export to Google BigQuery and use ACLs and views to scope the data shared with the auditor. This method provides robust querying capabilities, ensures that historical IAM policy changes can be analyzed effectively, and allows you to control access securely.
upvoted 1 times
...
joecloud12
3 months, 2 weeks ago
Selected Answer: B
b is correct because it is easier to implement compared to D
upvoted 1 times
...
H_S
4 months, 1 week ago
Selected Answer: D
READ THIS, ACL is not available in BIG QUERY , thereforeD. Enable Google Cloud Storage (GCS) log export to audit logs into a GCS bucket and delegate access to the bucket
upvoted 4 times
...
Jen3
8 months, 3 weeks ago
ACLs would provide year-round access to the data which is more privileges than necessary. Logs will need to be retained for a full year because hypothetically, January logs could be looked at in December. Cloud Storage offers signed URLs, and less expensive storage options.
upvoted 1 times
...
lisabisa
9 months ago
Both B and D are ok. Using cloud storage requires additional setup for auditors, pulling data to BQ. Using BQ would satisfy "streamline and expedite the analysis and audit process"
upvoted 1 times
...
Teckexam
10 months, 1 week ago
Selected Answer: B
Based on google documentation B is the correct answer. https://cloud.google.com/iam/docs/job-functions/auditing#scenario_external_auditors Dashboard is available in BigQuery to review historic logs and in case anamoly is found elevated access is provided. Access is revoked after audit activities are done.
upvoted 4 times
...
kip21
10 months, 1 week ago
D - Correct B - his option requires additional work to set up the ACLs and views to limit an auditor's view of the data. This could be time-consuming and complex to implement. Furthermore, BigQuery may not be the ideal tool for auditors who are only interested in reviewing Cloud IAM policy changes.
upvoted 2 times
...
CloudDom
1 year ago
Selected Answer: B
That‘s the only logical one also Bard is confirming this one
upvoted 1 times
...
thewalker
1 year ago
D I will not go with B, as the requirement is once for 12 months. Push the data in Coldline for 12 months and retrieve it during audit is enough. Save costs.
upvoted 3 times
thewalker
1 year ago
Coldline / Archive
upvoted 2 times
...
hogtrough
10 months, 2 weeks ago
Streamline and expedite analysis is the goal. Costs are never brought up.
upvoted 2 times
...
...
krisek
1 year, 1 month ago
Selected Answer: B
Reading from Cloud Storage raw audit logs (without filtering applied) is everything but streamlined. Imagine the auditor fetching all audit logs, then write some script to analyze them...
upvoted 2 times
...
Prakzz
1 year, 1 month ago
Selected Answer: D
B talks about ACL in BigQuery and ACL is not associated with BigQuery but with GCS.
upvoted 4 times
...
AdityaGupta
1 year, 1 month ago
Selected Answer: B
You want to streamline and expedite the analysis and audit process. Big Query, as the data retention is mentioned, and data is related to Cloud IAM policy changes, it is safe to assume long term retention with annual audit.
upvoted 1 times
...
TopTalk
1 year, 1 month ago
Selected Answer: B
``To comply with this requirement, a dashboard is available that provides access to the historic logs stored in BigQuery, and on request, to the Cloud Logging Admin Activity logs. The organization creates a Google group for these external auditors and adds the current auditor to the group. This group is monitored and is typically granted access to the dashboard application. During normal access, the auditors' Google group is only granted access to view the historic logs stored in BigQuery. If any anomalies are discovered, the group is granted permission to view the actual Cloud Logging Admin Activity logs via the dashboard's elevated access mode. At the end of each audit period, the group's access is then revoked.'' https://cloud.google.com/iam/docs/job-functions/auditing#scenario_external_auditors
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...