A security administrator needs to ensure that all administrative activities performed by privileged users within a specific Google Cloud project are immutable and retained for seven years to meet regulatory compliance requirements. They also need to ensure that these logs are not accidentally deleted or modified. Which combination of Cloud Logging features should be implemented?
- AConfigure a Log Sink to Pub/Sub and then to a custom SIEM with long-term archiving.
- BConfigure a _Required Log Bucket with a custom retention period and a lock.
- CConfigure a Log Sink to a BigQuery dataset with table expiration.
- DConfigure a Log Sink to Cloud Storage with object versioning enabled.
Show answer & explanationAnswer & explanation
Correct answer: B. Configure a _Required Log Bucket with a custom retention period and a lock.
A _Required Log Bucket (formerly 'default bucket' with advanced features) ensures that logs cannot be disabled or excluded. Setting a custom retention period of seven years fulfills the retention requirement, and applying a bucket lock makes the retention policy immutable, preventing accidental deletion or modification.
Why the other options are wrong
- A. This relies on an external SIEM for immutability and retention, which is out of Google Cloud's direct control for compliance guarantees and doesn't address the 'required' logging aspect within GCP.
- C. BigQuery table expiration can manage retention, but it doesn't guarantee immutability against modification/deletion or the 'required' aspect of the logging itself.
- D. While Cloud Storage with versioning helps prevent accidental deletion, a Log Sink can still be disabled, and it doesn't enforce 'required' logging or an immutable retention policy directly on the bucket for compliance.
Cloud Logging _Required Log Buckets with Locks
Special log buckets in Google Cloud Logging that cannot be disabled or excluded from routing, combined with a bucket lock to make their retention policy immutable, ensuring long-term, tamper-proof log storage for compliance.
- Ensures logs are always captured (required).
- Custom retention periods can be set.
- Bucket locks prevent retention policy changes or bucket deletion.
- Critical for regulatory compliance (e.g., GDPR, HIPAA, PCI DSS).
Memory trick: Required Buckets with Locks are like a 'digital vault' for your logs, making them 'required', 'retained', and 'immutable'.