A security engineer needs to ensure that all administrative activities performed by project owners within a Google Cloud organization are logged and retained for a minimum of seven years to meet compliance requirements. They also need to ensure these logs cannot be accidentally or maliciously deleted before their retention period expires. Which combination of Cloud Logging features should the engineer configure?
- AEnable Data Access logs for all services and configure a _Required Log Bucket with a retention lock.
- BEnable Admin Activity logs for all services and configure a _Required Log Bucket with a retention lock.
- CConfigure a log sink to a Cloud Pub/Sub topic and then to BigQuery for long-term storage.
- DConfigure a log sink to a Cloud Storage bucket with a retention policy.
Show answer & explanationAnswer & explanation
Correct answer: B. Enable Admin Activity logs for all services and configure a _Required Log Bucket with a retention lock.
Admin Activity logs record administrative actions and metadata, which is what 'administrative activities performed by project owners' refers to. Configuring a _Required Log Bucket ensures these logs are always routed to a specific bucket, and a retention lock prevents their deletion before the specified period, satisfying the compliance and immutability requirements.
Why the other options are wrong
- A. Data Access logs record API calls that read or modify user-provided data, not administrative activities like creating resources. Also, while _Required Log Buckets and retention locks are correct, the log type is wrong.
- C. Pub/Sub is a messaging service, not a long-term storage solution. BigQuery can store logs, but this setup doesn't intrinsically guarantee immutability or ensure *all* required logs are captured without _Required Log Buckets.
- D. While a log sink to Cloud Storage with retention is good, it doesn't guarantee immutability against malicious deletion or ensure *all* required logs are captured by default like _Required Log Buckets do.
Admin Activity Logs with Retention Lock
Admin Activity logs record API calls or administrative actions. When routed to a _Required Log Bucket with a retention lock, these logs are immutably stored for a specified duration, meeting stringent compliance needs.
- Admin Activity logs track administrative actions.
- _Required Log Buckets ensure mandatory log destinations.
- Retention locks prevent premature deletion for compliance.
Memory trick: Admin's actions are locked for seven years, no deleting!