Question 196 of 318
Choose 2As part of your organization's zero trust strategy, you use Identity-Aware Proxy (IAP) to protect multiple applications. You need to ingest logs into a Security Information and Event Management (SIEM) system so that you are alerted to possible intrusions.
Which logs should you analyze?
✓AData Access audit logs
BPolicy Denied audit logs
CCloud Identity user log events
DAdmin Activity audit logs
A• organization poli-cy:constraints/gcp.restrictStorageNonCmekServices
• binding at: org1
• policy type: allow
• policy value: all supported services
• binding at: org1
• policy type: allow
• policy value: all supported services
✓B• organization policy: con-straints/gcp.restrictNonCmekServices
• binding at: org1
• policy type: deny
• policy value: storage.googleapis.com
• binding at: org1
• policy type: deny
• policy value: storage.googleapis.com
C• organization policy: con-straints/gcp.restrictStorageNonCmekServices
• binding at: org1
• policy type: deny
• policy value: storage.googleapis.com
• binding at: org1
• policy type: deny
• policy value: storage.googleapis.com
D• organization policy: con-straints/gcp.restrictNonCmekServices
• binding at: org1
• policy type: allow
• policy value: storage.googleapis.com
• binding at: org1
• policy type: allow
• policy value: storage.googleapis.com
✓
Correct Answer: A, B
Data Access audit logs
▥
Explanation
The correct answer is highlighted above. Review the wording carefully, then use the next question to continue building your understanding of Google certification topics.