Professional Cloud Security EngineerEnsuring data protectionMedium
A security team needs to ensure that all administrative activities performed on Google Cloud resources, especially those related to data protection and access control, are immutable and provable for audit purposes for a period of 10 years. This includes changes to IAM policies, Cloud Storage bucket configurations, and KMS key rings. How can they achieve this immutability for audit logs?
- AEnable Cloud Logging data retention policies for 10 years.
- BStream Cloud Audit Logs to BigQuery and set a table expiration policy.
- CExport Cloud Audit Logs to a Cloud Storage bucket with Object Versioning enabled.
- DConfigure Cloud Audit Logs to export to a Cloud Storage bucket with a Bucket Lock policy.
Show answer & explanationAnswer & explanation
Correct answer: D. Configure Cloud Audit Logs to export to a Cloud Storage bucket with a Bucket Lock policy.
To ensure immutability and provability for audit logs, exporting Cloud Audit Logs to a Cloud Storage bucket with a Bucket Lock policy is the most effective solution. Bucket Lock enforces a retention policy that prevents objects (the log files) from being deleted or modified for a specified duration, even by administrators, satisfying the immutability requirement.
Why the other options are wrong
- A. Cloud Logging data retention policies apply to logs within Cloud Logging, but for true immutability and long-term WORM compliance, exporting to a locked Cloud Storage bucket is superior.
- B. Streaming to BigQuery and setting a table expiration policy only ensures deletion after a period, not immutability or protection against modification during that period.
- C. Object Versioning keeps multiple versions but doesn't prevent deletion of all versions or modification of the current version if not locked.
Cloud Audit Logs with Bucket Lock
Exporting Cloud Audit Logs to a Cloud Storage bucket that has a Bucket Lock policy applied, ensuring the logs are immutable and cannot be deleted or modified for a specified retention period.
- Provides WORM compliance for audit trails.
- Essential for regulatory and legal requirements.
- Protects against tampering, even by privileged users.
Memory trick: Lock your logs in storage to keep them forever true.