After a security incident you need simple monitoring for unexpected firewall changes and instance creation. What is the simplest recommended solution?
Choose an answer
Tap an option to check your answer.
Correct answer: Use Cloud Logging filters to create log-based metrics for firewall and instance actions, then monitor those metrics and set alerts..
Why this is the answer
The simplest recommended solution is to use Cloud Logging filters to create log-based metrics. Cloud Audit Logs automatically capture administrative activities like firewall changes and instance creation. By creating log-based metrics, you can count these specific events. Then, you can easily monitor these metrics in Cloud Monitoring and set up alerts to notify you immediately of any unexpected activity. This approach leverages built-in Google Cloud services, requiring minimal setup and maintenance. Creating a log sink to Cloud Storage and using BigQuery is more complex and suitable for deeper, historical analysis, not simple real-time monitoring. Installing Kibana on a VM introduces external software and management overhead, making it less simple. Enabling firewall rules logging is useful but only covers firewall changes, not instance creation, and doesn't inherently provide a simple alerting mechanism for unexpected events across both.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed