Professional Cloud Security EngineerManaging operationsHard

A large enterprise has a complex Google Cloud environment with hundreds of projects and multiple teams. They need to ensure that all Cloud Audit Logs (Admin Activity, Data Access, and System Event) from all projects are centrally collected, retained for 10 years, and made available for security analysis in a dedicated security project. They also want to ensure that these logs are not accidentally or maliciously deleted before their retention period. Which logging strategy should they implement?

  1. AEnable _Required Log Buckets at the organization level with a 10-year retention policy and a lock, and create a Pub/Sub topic to stream logs to BigQuery for analysis.
  2. BCreate a log sink in each project to export all logs to a central Cloud Storage bucket with a 10-year retention policy and object lock.
  3. CConfigure an aggregated log sink at the organization level to route all logs to a dedicated log bucket in the security project with a 10-year retention policy and a lock.
  4. DDeploy a custom logging agent on each Compute Engine instance to capture logs and send them to a central Splunk instance hosted on Google Cloud.
Show answer & explanation

Correct answer: C. Configure an aggregated log sink at the organization level to route all logs to a dedicated log bucket in the security project with a 10-year retention policy and a lock.

An aggregated log sink at the organization level is the most efficient way to centralize logs from all projects. Routing them to a dedicated log bucket with a 10-year retention policy and a lock ensures immutability and compliance with the deletion requirement.

Why the other options are wrong

  • A. _Required Log Buckets only capture Admin Activity and Data Access logs, missing System Event logs. While providing immutability, it doesn't cover all specified log types for the 'all Cloud Audit Logs' requirement. Streaming to BigQuery is for analysis, not the primary long-term immutable storage for all logs.
  • B. Creating individual log sinks in hundreds of projects is not scalable and prone to misconfiguration. Cloud Storage object lock is for objects, not the bucket itself, and a locked log bucket provides stronger immutability.
  • D. This solution is for application-level logs from Compute Engine, not Cloud Audit Logs from all Google Cloud services. It is overly complex, requires significant management, and doesn't leverage native Google Cloud logging features for audit logs.

Aggregated Log Sinks with Locked Log Buckets

A Google Cloud Logging strategy to centralize all Cloud Audit Logs from an entire organization to a single, immutable log bucket with a long-term retention policy to meet compliance and security analysis needs.

  • Aggregated sinks collect logs from all projects/folders in an organization.
  • Dedicated log buckets provide centralized, isolated storage.
  • Locked retention policies ensure immutability and prevent deletion.
  • Covers Admin Activity, Data Access, and System Event logs.

Memory trick: Aggregated sinks gather all logs, and a locked bucket keeps them forever safe.

More Managing operations questions