A security engineer needs to configure Cloud Monitoring to detect when a Google Cloud Storage (GCS) bucket's `uniformBucketLevelAccess` property is disabled. This change could indicate a potential security misconfiguration, as it would allow object-level ACLs to be used, potentially leading to unintended public access. Which MQL query should the engineer use to create an alerting policy for this specific condition?
- Afetch gcs_bucket | metric 'logging.googleapis.com/log_entry_count' | filter jsonPayload.protoPayload.methodName = 'storage.buckets.update' AND jsonPayload.protoPayload.request.uniformBucketLevelAccess = false
- Bfetch gcs_bucket | metric 'logging.googleapis.com/log_entry_count' | filter jsonPayload.methodName = 'storage.buckets.update' AND jsonPayload.request.uniformBucketLevelAccess = false
- Cfetch gcs_bucket | metric 'logging.googleapis.com/log_entry_count' | filter jsonPayload.methodName = 'storage.buckets.update' AND jsonPayload.protoPayload.methodName = 'storage.buckets.update' AND jsonPayload.protoPayload.request.uniformBucketLevelAccess = false
- Dfetch gcs_bucket | metric 'logging.googleapis.com/log_entry_count' | filter jsonPayload.methodName = 'storage.buckets.update' AND jsonPayload.resource.type = 'gcs_bucket' AND jsonPayload.resource.labels.bucket_name = 'YOUR_BUCKET_NAME' AND jsonPayload.event_type = 'google.storage.admin.BucketUpdate' AND jsonPayload.request.bucket.uniformBucketLevelAccess = false
Show answer & explanationAnswer & explanation
Correct answer: A. fetch gcs_bucket | metric 'logging.googleapis.com/log_entry_count' | filter jsonPayload.protoPayload.methodName = 'storage.buckets.update' AND jsonPayload.protoPayload.request.uniformBucketLevelAccess = false
The correct MQL query needs to accurately filter for GCS bucket update operations and specifically check the `uniformBucketLevelAccess` property within the `protoPayload.request` field. Option D correctly identifies these nested fields, which are typical for Cloud Audit Logs within Cloud Logging entries.
Why the other options are wrong
- B. This option incorrectly places `jsonPayload.request.uniformBucketLevelAccess` directly under `jsonPayload`, which is not the correct path for this information in Cloud Audit Logs. It also lacks `protoPayload`.
- C. This option attempts to filter both `jsonPayload.methodName` and `jsonPayload.protoPayload.methodName`, which is redundant and can lead to incorrect results or no matches. The `protoPayload` is the primary structure for audit log details.
- D. This option includes several incorrect or redundant filters like `jsonPayload.resource.type`, `jsonPayload.resource.labels.bucket_name`, and `jsonPayload.event_type`, which are not standard or necessary for this specific log entry structure. The path to `uniformBucketLevelAccess` is also incorrect.
Cloud Monitoring MQL for Audit Logs
Cloud Monitoring Query Language (MQL) can be used to query and filter Cloud Audit Logs ingested into Cloud Logging, enabling the creation of custom alerts for specific security-related events or misconfigurations.
- MQL allows complex filtering and aggregation of log entries.
- Audit logs contain `protoPayload` with detailed request/response information.
- Alerts can be triggered based on specific field values within log entries.
Memory trick: MQL filters audit logs to catch bucket access changes, ensuring uniform security.