You must record all read requests to sensitive objects in a Cloud Storage bucket for legal auditing. What should you enable?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable Data Access audit logs for the Cloud Storage API..
Why this is the answer
Enabling Data Access audit logs for the Cloud Storage API is the correct solution because these logs record API calls that read or modify data within a project, including read requests to Cloud Storage objects. This directly addresses the requirement for legal auditing of sensitive object access. Identity-Aware Proxy (IAP) controls access to applications running on Google Cloud, not directly to Cloud Storage object read requests. The Data Loss Prevention (DLP) API scans for sensitive data but doesn't log read requests. Allowing only a single service account permission is a security measure, but it doesn't provide an audit trail of when that service account accessed the data.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed