Soru

Zorluk: KolayMonitoring, Logging, and Observability Integration

An enterprise operations team needs to establish a centralized observability strategy across multiple Google Cloud projects. They must securely aggregate Cloud Audit Logs into BigQuery for security analytics while ensuring key operational alerts are triggered without exposing telemetry data to exfiltration risks. Which TWO configurations should the team implement to achieve these observability requirements?

  1. Configure an aggregated Log Router sink at the organization level with a BigQuery dataset destination and a filter targeting Cloud Audit Logs.Cevap
  2. B
    Apply an aggregate Cloud Logging exclusion filter at the organization level to drop all log entries with severity ERROR and above to manage ingestion throughput.
  3. Grant fine-grained predefined roles such as Logging Admin and Monitoring Notification Channel Editor to operational service accounts instead of primitive roles.Cevap
  4. D
    Assign the primitive Owner role to service accounts responsible for managing log export sinks to ensure unrestricted access across all monitoring resources.
  5. E
    Rely strictly on project-level IAM permissions to prevent authorized service accounts from exfiltrating log data to unauthorized external storage destinations.

Cevap

The team should configure an aggregated Log Router sink at the organization level targeting BigQuery for audit logs and grant fine-grained predefined IAM roles to operational service accounts.
Configuring an aggregated Log Router sink at the organization level allows central streaming of Cloud Audit Logs to BigQuery across all constituent projects. Complementing this with fine-grained predefined IAM roles ensures service accounts possess only necessary permissions for operational monitoring and log routing without over-privilege.

Adım Adım Çözüm

1
Identify the proper GCP observability feature for centralized log aggregation across multi-project organizations.
An organization-level aggregated Log Router sink configured with a BigQuery destination and appropriate log filtering meets audit logging and analytical querying requirements efficiently.
Aggregated sinks collect log entries from child projects centrally without requiring manual per-project sink setup.
2
Select the appropriate access management posture for operational logging and monitoring service accounts.
Assign predefined, minimal-permission roles such as Logging Admin and Monitoring Notification Channel Editor.
Predefined roles align with IAM best practices by avoiding over-privileged primitive roles while enabling complete monitoring automation.

Anahtar Kavram

Centralized Log Aggregation and Observability IAM Least Privilege
Bu soruyu puanla