Medium1 markMultiple Choice
Domain 5.3: Viewing audit logsCloud LoggingLog SinksAudit LogsCloud Storage

GCP ACE · Question 47 · Domain 5.3: Viewing audit logs

Your compliance team requires that all Data Access audit logs be retained for 3 years for forensic analysis. Cloud Logging only retains these logs for 30 days by default.

Which TWO actions should you take to meet this requirement? (Select TWO)

Answer options:

A.

Create a Log Sink in Cloud Logging.

B.

Increase the retention period of the _Default log bucket to 3 years.

C.

Set the destination of the Log Sink to a Cloud Storage bucket with an Archive storage class.

D.

Set the destination of the Log Sink to Cloud SQL.

E.

Configure a Cloud Function to download logs daily.

How to approach this question

Identify the mechanism for exporting logs and the most cost-effective storage for long-term retention.

Full Answer

To retain logs beyond the default period cost-effectively, you should create a Log Router Sink. The sink filters the logs you want and routes them to a destination. For 3-year compliance retention where data is rarely accessed, a Cloud Storage bucket (specifically the Archive class) is the best practice.

Common mistakes

Trying to store years of logs directly in Cloud Logging, which is expensive.

Practice the full GCP Associate Cloud Engineer Practice Exam 2

50 questions · hints · full answers · grading

More questions from this exam