Auditors request all Cloud IAM policy changes from the past 12 months. How can you streamline auditing and securely share only the relevant data?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable Logging export to Google BigQuery and use ACLs and views to scope the data shared with the auditor.
Why this is the answer
Exporting Cloud Audit Logs to BigQuery provides a robust, scalable, and queryable solution for auditing. BigQuery's strong access control features (ACLs) and views allow you to precisely scope the data, ensuring auditors only see the relevant IAM policy changes without exposing other sensitive information. This method is efficient for large datasets over a 12-month period. Custom Stackdriver (now Cloud Monitoring) alerts are for real-time notifications, not for historical data sharing. Cloud Functions transferring logs to Cloud SQL is an overly complex and less scalable solution compared to BigQuery for large-scale log analysis. Exporting to GCS is possible, but querying logs directly in GCS is less efficient than BigQuery, and managing granular access to specific log entries within GCS buckets is more challenging than using BigQuery views.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed