Soru

Zorluk: KolayMonitoring, Logging, and Observability Integration

An enterprise architecture team is establishing an observability framework for custom applications running on Google Cloud Compute Engine instances across multiple production projects. They need to collect both system metrics and application logs, and aggregate critical logs into a centralized log repository in a dedicated security project. Which TWO actions should you take to meet these requirements using Google Cloud recommended practices? (Select TWO)

  1. Install and configure the Ops Agent on the Compute Engine instances to collect and transmit system metrics and application logs to Cloud Logging and Cloud Monitoring.Cevap
  2. B
    Assign the primitive Owner role (roles/owner) to the instance service account to grant complete access for writing telemetry and logs across the organization.
  3. Configure an aggregated Log Router sink at the organization or folder level to route log entries from all production projects to a central Cloud Logging log bucket.Cevap
  4. D
    Create an aggregate log exclusion filter that drops all ERROR and AUDIT severity logs to prevent log ingestion costs from exceeding budget limits.
  5. E
    Rely exclusively on standard IAM permissions to control log access without configuring VPC Service Controls around log destination buckets.

Cevap

The two correct actions are to install the Ops Agent on the Compute Engine instances to collect metrics and logs, and to set up an aggregated Log Router sink at the organization level to direct logs to a central log bucket.
Installing the Ops Agent ensures complete telemetry ingestion (system metrics and application logs) from Compute Engine instances. Using an aggregated Log Router sink at the organization or folder level efficiently collects and centralizes logs across multiple projects into a designated security log bucket.

Adım Adım Çözüm

1
Deploy telemetry collection agent on workloads
Install the Ops Agent on VM instances to capture host-level metrics and application log streams.
The Ops Agent combines logging and monitoring telemetry into a single efficient agent optimized for Compute Engine.
2
Configure multi-project log aggregation
Create an aggregated Log Router sink targeting a central log bucket in the security project.
Aggregated sinks provide enterprise-wide centralization of audit and operational logs without needing manual project-by-project sink configurations.

Anahtar Kavram

Centralized observability integration using the Google Cloud Ops Agent and Aggregated Log Router sinks.
Bu soruyu puanla