Courseiva

Cloud Digital Leader Trust and security with Google Cloud Practice Question

Exhibit

Refer to the exhibit.
```
$ gcloud logging read "resource.type=project AND severity=ERROR" --limit 5
timestamp: 2023-10-05T10:30:00Z
protoPayload:
  methodName: "storage.objects.get"
  authenticationInfo:
    principalEmail: "user@example.com"
  resourceName: "projects/_/buckets/my-bucket/objects/secret.pdf"
```

Refer to the exhibit. A security administrator reviews this Cloud Audit Logs entry. What does this entry indicate?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The user attempted to read the object 'secret.pdf' and the request resulted in an error.

The correct option is A: the user attempted to read the object 'secret.pdf' and the request resulted in an error. In Cloud Audit Logs, a data-access entry for a storage object typically records a method such as storage.objects.get, which corresponds to reading/downloading an object, and the presence of an error/status field (for example, a non-OK status or error code) indicates the request failed rather than succeeded. Option D is wrong because a successful read would show a successful status without an error result. Option B is wrong because updating an IAM policy would appear as a setIamPolicy operation on the bucket, not an object read. Option C is wrong because deleting an object would be logged as storage.objects.delete, not a read/get operation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The user attempted to read the object 'secret.pdf' and the request resulted in an error.

    Why this is correct

    The audit entry records a data-access operation on the object secret.pdf, with a status field showing the request failed. This confirms the user attempted a read and the operation returned an error rather than succeeding.

  • ✗

    The user updated the IAM policy on the bucket.

    Why it's wrong here

    The log records a bucket-level IAM operation, not an object-level action, so it cannot indicate a policy update. It is tempting because bucket IAM changes appear in Cloud Audit Logs, but the method and resource fields in the exhibit point to an object read instead.

  • ✗

    The user attempted to delete the object 'secret.pdf'.

    Why it's wrong here

    The entry shows a successful read, not a delete attempt; deletion would log a different method such as storage.objects.delete. It is tempting because delete events are common audit entries, but the recorded method and status confirm the object was accessed, not removed.

  • ✗

    The user successfully read the object 'secret.pdf'.

    Why it's wrong here

    The log entry records a bucket-level administrative change rather than an object read, so it does not show 'secret.pdf' being read. It is tempting because object reads are frequently audited, but the resource and method fields here identify a bucket configuration action.

About these practice questions

This GCDL question is part of Courseiva's 848-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.