Retain BigQuery data access logs for six months and ensure only audit personnel across all projects can access them. Which logging export strategy meets this requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: Export data access logs via an aggregated export sink to a Cloud Storage bucket in a newly created project for audit logs and restrict access to the project that contains the exported logs.
Why this is the answer
The correct option uses an aggregated export sink, which allows you to export logs from all projects in an organization to a single destination. This centralizes log management, making it easier to enforce consistent retention policies and access controls for audit personnel across the entire organization. Storing these logs in a dedicated project further isolates them from operational data, enhancing security. Restricting access to this dedicated project ensures only authorized audit personnel can view the logs. The other options are less effective: Enabling logs in each project and restricting Stackdriver Logging access is inefficient for managing access across many projects and doesn't centralize storage. Exporting to a Cloud Storage bucket in each Data Analyst's project creates fragmented storage and makes centralized access control difficult. Exporting via a project-level sink to a new project still requires configuring exports for each individual project, which is not scalable for an organization-wide requirement.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed