nerdexam
Google

PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #65

You need to ingest audit logs from your organization's entire Google Cloud environment into Google Security Operations (SecOps). This process must include Cloud NAT logs for workloads within a…

The correct answer is C. Configure an aggregated log sink at the folder level, and route the Cloud NAT logs to Pub/Sub. The most efficient approach is to create an aggregated log sink at the folder level that captures Cloud NAT logs and routes them to Pub/Sub. Then, enable the Pub/Sub connector in Google SecOps to ingest these logs. This approach minimizes complexity by handling all projects in…

Managing data ingestion and parsing

Question

You need to ingest audit logs from your organization's entire Google Cloud environment into Google Security Operations (SecOps). This process must include Cloud NAT logs for workloads within a designated folder. You need to configure this ingestion while minimizing integration complexity. You have already enabled Google Cloud data ingestion into Google SecOps. What should you do next?

Options

  • ACreate a custom filter to export the folder-level Cloud NAT logs.
  • BCreate a custom filter to export the project-level Cloud NAT logs for each project in the
  • CConfigure an aggregated log sink at the folder level, and route the Cloud NAT logs to Pub/Sub.
  • DConfigure an aggregated log sink at the organization level, and route the Cloud NAT logs to a

How the community answered

(20 responses)
  • A
    5% (1)
  • B
    5% (1)
  • C
    80% (16)
  • D
    10% (2)

Explanation

The most efficient approach is to create an aggregated log sink at the folder level that captures Cloud NAT logs and routes them to Pub/Sub. Then, enable the Pub/Sub connector in Google SecOps to ingest these logs. This approach minimizes complexity by handling all projects in the folder collectively and leverages managed integration for seamless ingestion.

Topics

#aggregated log sink#Cloud NAT logs#folder-level ingestion#Google Cloud audit logs

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER Practice