PCSE Practice Question: Managing Operations in a Cloud Solution Environment
A security team needs to detect and respond to a potential data exfiltration via VPC Flow Logs. They want to identify traffic to known malicious IP addresses in real-time. Which architecture should they use?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a log sink to send VPC Flow Logs to Pub/Sub, trigger a Cloud Function that checks IP addresses against a threat list and sends alerts.
VPC Flow Logs can be streamed via a log sink to Pub/Sub, then processed by Cloud Functions to compare against a threat feed. BigQuery is for analysis, not real-time. Dataflow could be used but is more complex. Cloud NAT is unrelated.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a log sink to send VPC Flow Logs to Pub/Sub, trigger a Cloud Function that checks IP addresses against a threat list and sends alerts.
Why this is correct
This architecture provides near real-time detection via streaming Pub/Sub and serverless processing.
- ✗
Enable VPC Flow Logs and use Dataflow to stream logs to a third-party SIEM.
Why it's wrong here
While possible, it is not the simplest real-time detection method; the question asks for detection and response.
- ✗
Use Cloud NAT to block traffic to malicious IPs based on a predefined list.
Why it's wrong here
Cloud NAT is for outbound connectivity, not detection.
- ✗
Export VPC Flow Logs to BigQuery and schedule a query every minute to check for matches.
Why it's wrong here
BigQuery is not designed for real-time streaming; minute latency is not real-time.
Visual reference
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCSE question from scratch — 960 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCSE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCSE exam.