Google Associate Cloud EngineerConfiguring access and securityHard
A data privacy officer needs to ensure that all access attempts to sensitive customer data stored in Google Cloud Storage buckets are logged, regardless of whether the access was successful or denied. These logs are critical for forensic analysis in case of a data breach. Which type of audit log should they enable and monitor?
- AData Access logs
- BSystem Event logs
- CAdmin Activity logs
- DCloud Trace logs
Show answer & explanationAnswer & explanation
Correct answer: A. Data Access logs
Data Access logs record API calls that read or modify user-provided data within Google Cloud resources, such as Cloud Storage. To capture all access attempts to sensitive customer data, including successful and denied attempts, Data Access logs must be explicitly enabled for the relevant services and configured to log 'DATA_READ' and 'DATA_WRITE' operations.
Why the other options are wrong
- B. System Event logs track actions by Google systems, not user or service account access to data.
- C. Admin Activity logs record administrative actions, not access to user-provided data.
- D. Cloud Trace is for distributed tracing and performance monitoring, not for auditing data access.
Data Access Logs
Data Access logs record API calls that read or modify user-provided data within Google Cloud resources.
- Must be explicitly enabled for specific services (e.g., Cloud Storage).
- Captures 'DATA_READ' and 'DATA_WRITE' operations.
- Essential for auditing access to sensitive data for compliance and security.
Memory trick: Data logs are the watchdogs for your precious data.