Professional Cloud Security EngineerEnsuring data protectionMedium

A security team needs to ensure that all administrative activities performed on Google Cloud Storage buckets, such as creating, deleting, or modifying bucket policies, are logged for auditing purposes and retained for a minimum of seven years in an immutable format. Which logging configuration should they implement?

  1. AEnable Data Access logs for Cloud Storage and export them to BigQuery.
  2. BEnable Admin Activity logs for Cloud Storage and configure a Cloud Storage bucket as a sink with a retention policy.
  3. CEnable Admin Activity logs for Cloud Storage and export them to a Pub/Sub topic for real-time processing.
  4. DEnable System Event logs for Cloud Storage and stream them to Security Command Center.
Show answer & explanation

Correct answer: B. Enable Admin Activity logs for Cloud Storage and configure a Cloud Storage bucket as a sink with a retention policy.

Admin Activity logs record administrative actions, including creating, deleting, or modifying bucket policies. Exporting these logs to a Cloud Storage bucket configured as a sink, with an appropriate retention policy and Object Lock enabled, will ensure they are retained for seven years in an immutable format for auditing.

Why the other options are wrong

  • A. Data Access logs record user data access, not administrative activities on buckets. Exporting to BigQuery is for analytics, not necessarily immutable long-term retention.
  • C. Exporting to Pub/Sub is for real-time processing, not for immutable long-term retention. A further destination like Cloud Storage with retention would still be needed.
  • D. System Event logs primarily cover Google-generated events, not user administrative actions. Streaming to Security Command Center is for threat detection, not long-term immutable audit logging.

Cloud Audit Logs with WORM Storage

Enabling Cloud Audit Logs (specifically Admin Activity logs) for Google Cloud Storage and exporting them to a Cloud Storage bucket configured with a retention policy and Object Lock to ensure immutable, long-term storage for compliance and auditing.

  • Admin Activity logs capture administrative actions.
  • Cloud Storage bucket with retention policy ensures specified retention.
  • Object Lock provides WORM (Write Once, Read Many) immutability.
  • Essential for meeting audit and compliance requirements.

Memory trick: For audit logs, choose Admin Activity, sink to Storage, and Lock for eternity!

More Ensuring data protection questions