Professional Cloud Security EngineerManaging operationsMedium

A security analyst needs to investigate a potential data exfiltration incident. They suspect that a compromised service account might have been used to access and download data from a Cloud Storage bucket. The investigation requires detailed records of every API call made by the service account, including the source IP address and the specific data accessed. Which type of Cloud Audit Log should the analyst focus on to retrieve this information?

  1. AData Access logs
  2. BPolicy Denied logs
  3. CAdmin Activity logs
  4. DSystem Event logs
Show answer & explanation

Correct answer: A. Data Access logs

Data Access logs record API calls that read the configuration or metadata of resources, as well as user-provided data. This includes operations like reading data from Cloud Storage buckets, which is crucial for investigating data exfiltration. Admin Activity logs cover resource configuration changes, not data access.

Why the other options are wrong

  • B. Policy Denied logs are not a standard category within Cloud Audit Logs; policy denial events would typically be found within Admin Activity or Data Access logs, or as specific security findings.
  • C. Admin Activity logs record administrative operations that modify resource configurations or metadata, not data access itself.
  • D. System Event logs cover Google Cloud system-level events that affect resources, not user data access.

Cloud Audit Logs: Data Access logs

Data Access logs record API calls that read the configuration or metadata of resources, as well as user-provided data. These logs are not enabled by default for all resource types due to their volume and are typically used for auditing data access.

  • Records reading/writing of user-provided data.
  • Crucial for data exfiltration investigations.
  • Often disabled by default to manage log volume.

Memory trick: Admin changes, Data reads, System events.

More Managing operations questions