Professional Cloud Security EngineerManaging operationsMedium

A security engineer is investigating a potential data exfiltration incident. They need to determine if any sensitive data was accessed by unauthorized parties. They specifically need to review logs of read operations on Cloud Storage buckets that contain customer data. To ensure these logs are available for forensic analysis, they must be retained for at least one year. Which type of Cloud Audit Logs should the engineer focus on, and how should they ensure its retention?

  1. AAdmin Activity logs; configure a custom log sink to a Cloud Storage bucket with a 1-year retention policy.
  2. BPolicy Denied logs; configure a custom log sink to Pub/Sub and then to a BigQuery dataset with a 1-year retention.
  3. CData Access logs; enable at the bucket level and configure a 1-year retention policy on the associated log bucket.
  4. DSystem Event logs; enable at the project level and configure a 1-year retention policy on the associated log bucket.
Show answer & explanation

Correct answer: C. Data Access logs; enable at the bucket level and configure a 1-year retention policy on the associated log bucket.

Data Access logs record read operations on data, which is crucial for investigating data exfiltration. These logs must be explicitly enabled for Cloud Storage buckets and their retention policy configured on the log bucket where they reside.

Why the other options are wrong

  • A. Admin Activity logs record administrative actions, not data read operations. While a custom sink can set retention, the wrong log type is chosen.
  • B. Policy Denied logs record attempts blocked by IAM policies, not successful data access. While Pub/Sub to BigQuery can store logs, the wrong log type is chosen for the investigation.
  • D. System Event logs record Google Cloud system actions, not user data access. Enabling at the project level is correct for some log types, but not for detailed data access.

Data Access Logs

Cloud Audit Logs that record API calls that read or modify user-provided data within Google Cloud services, such as Cloud Storage or BigQuery.

  • Records data read/write operations.
  • Must be explicitly enabled for most services (e.g., Cloud Storage).
  • Crucial for data exfiltration investigations.
  • Can incur costs due to high volume.

Memory trick: Data Access logs show who tried to access your data's treasure chest.

More Managing operations questions