A security auditor needs to verify that all API calls made by administrators within a Google Cloud organization are logged, immutable, and retained for a minimum of one year. They specifically need to ensure that these logs are not altered or deleted, even by project owners. Which type of Cloud Audit Log should be enabled, and what logging configuration should be applied to meet the immutability and retention requirements?
- AData Access logs enabled for all services, exported to Cloud Storage with retention policy.
- BSystem Event logs enabled for all resources, exported to BigQuery with table expiration.
- CAdmin Activity logs with basic logging, routed to Pub/Sub for external SIEM retention.
- DAdmin Activity logs enabled by default, routed to a locked _Required Log Bucket with 1-year retention.
Show answer & explanationAnswer & explanation
Correct answer: D. Admin Activity logs enabled by default, routed to a locked _Required Log Bucket with 1-year retention.
Admin Activity logs are enabled by default and record API calls that modify resources, which is what 'API calls made by administrators' refers to. Routing these logs to a _Required Log Bucket ensures they cannot be disabled. Applying a bucket lock makes the configured 1-year retention immutable, preventing alteration or deletion even by privileged users.
Why the other options are wrong
- A. Data Access logs are for data read/write, not administrative API calls. Cloud Storage retention alone doesn't guarantee immutability against deletion by owners without a lock.
- B. System Event logs are for Google-managed resource changes. BigQuery table expiration doesn't guarantee immutability against deletion or modification of the data itself.
- C. Routing to an external SIEM relies on the SIEM's controls, not GCP's, and 'basic logging' doesn't explicitly guarantee immutability within GCP before export.
Admin Activity Logs with Locked _Required Log Buckets
Admin Activity logs record API calls that modify resource configurations. When routed to a _Required Log Bucket with a bucket lock, these logs become immutable and cannot be disabled, altered, or deleted, ensuring compliance for administrative actions.
- Admin Activity logs are enabled by default for auditing administrative actions.
- _Required Log Buckets ensure logs are always collected.
- Bucket locks make retention policies immutable, preventing deletion/modification.
- Crucial for compliance and forensic analysis of administrative changes.
Memory trick: Admin Activity in a 'Locked Required Bucket' means your audit trail is 'safe and sound' for 'ages'.