Google
PROFESSIONAL-DATA-ENGINEER · Question #224
Data Analysts in your company have the Cloud IAM Owner role assigned to them in their projects to allow them to work with multiple GCP products in their projects. Your organization requires that all…
The correct answer is D. Export the data access logs via an aggregated export sink to a Cloud Storage bucket in a newly created project for audit logs. Restrict access to the project that. Explanation/Reference: https://cloud.google.com/iam/docs/roles-audit-logging#scenario_external_auditors
Submitted by mike_84· Mar 30, 2026Ensuring solution quality
Question
Data Analysts in your company have the Cloud IAM Owner role assigned to them in their projects to allow them to work with multiple GCP products in their projects. Your organization requires that all BigQuery data access logs be retained for 6 months. You need to ensure that only audit personnel in your company can access the data access logs for all projects. What should you do?
Options
- AEnable data access logs in each Data Analyst's project. Restrict access to Stackdriver Logging via Cloud IAM roles.
- BExport the data access logs via a project-level export sink to a Cloud Storage bucket in the Data Analysts' projects. Restrict access to the Cloud Storage
- CExport the data access logs via a project-level export sink to a Cloud Storage bucket in a newly created projects for audit logs. Restrict access to the project
- DExport the data access logs via an aggregated export sink to a Cloud Storage bucket in a newly created project for audit logs. Restrict access to the project that
How the community answered
(42 responses)- A19% (8)
- B5% (2)
- C7% (3)
- D69% (29)
Explanation
Explanation/Reference: https://cloud.google.com/iam/docs/roles-audit-logging#scenario_external_auditors
Topics
#audit logs#aggregated export sink#log retention#Cloud IAM
Community Discussion
No community discussion yet for this question.