Professional Cloud Security EngineerEnsuring data protectionMedium
A company is storing highly sensitive financial transaction data in Cloud Storage buckets. They require an immutable audit trail of all data access and modifications, including who accessed what, when, and from where, for compliance purposes. This audit trail must be retained for seven years and be tamper-proof. Which Google Cloud service combination should be used?
- ACloud Logging with Cloud Audit Logs and export to Cloud SQL.
- BCloud Logging with Cloud Audit Logs and export to BigQuery.
- CCloud Monitoring with custom metrics and alerts.
- DCloud Audit Logs with export to a WORM-compliant Cloud Storage bucket.
Show answer & explanationAnswer & explanation
Correct answer: D. Cloud Audit Logs with export to a WORM-compliant Cloud Storage bucket.
Cloud Audit Logs automatically records administrative activities and data access for Cloud Storage. Exporting these logs to a Cloud Storage bucket configured with Object Lock in WORM (Write Once, Read Many) mode ensures immutability and long-term retention for compliance, making the audit trail tamper-proof for seven years.
Why the other options are wrong
- A. Cloud SQL is a relational database and is not typically used for long-term, immutable audit log storage; it also lacks WORM capabilities.
- B. While BigQuery can store logs, it doesn't inherently provide the WORM immutability guarantee required for a tamper-proof audit trail.
- C. Cloud Monitoring focuses on operational metrics and alerts, not detailed, tamper-proof audit logs.
Cloud Audit Logs with WORM Storage
Google Cloud's built-in auditing service combined with immutable storage to create tamper-proof records of activity for compliance.
- Records admin and data access events.
- WORM (Write Once, Read Many) ensures immutability.
- Critical for regulatory compliance and forensic analysis.
Memory trick: Audit logs go to WORM, forever sealed and never reformed.