Professional Cloud Security EngineerManaging operationsHard

A security team is investigating a series of unusual network connections originating from a Compute Engine instance. They need to determine if any firewall rules have been recently modified or created that could permit this suspicious outbound traffic, and by whom. Additionally, they want to understand the potential impact of these rules. Which Google Cloud service combination would be most effective for this investigation?

  1. ACloud Audit Logs for Admin Activity, combined with Policy Intelligence's Policy Analyzer.
  2. BSecurity Command Center's Event Threat Detection and Security Health Analytics.
  3. CCloud Monitoring for network metrics and Cloud Logging for `compute.firewalls.update` events.
  4. DCloud Logging for Data Access logs and Web Security Scanner.
Show answer & explanation

Correct answer: A. Cloud Audit Logs for Admin Activity, combined with Policy Intelligence's Policy Analyzer.

Cloud Audit Logs (specifically Admin Activity logs) will show who modified or created firewall rules. Policy Intelligence's Policy Analyzer can then be used to analyze existing or proposed firewall rules to understand their potential impact and reachability, confirming if they allow the suspicious traffic and helping assess the blast radius.

Why the other options are wrong

  • B. Event Threat Detection focuses on general threats from logs, and Security Health Analytics on misconfigurations. Neither directly provides the 'who' of a specific firewall rule change or advanced impact analysis of rules.
  • C. Cloud Monitoring shows network metrics but not who changed firewall rules or their detailed impact. `compute.firewalls.update` events are in Admin Activity logs, not a general Cloud Logging search.
  • D. Data Access logs are for data operations, not firewall rule changes. Web Security Scanner is for web application vulnerabilities, irrelevant here.

Policy Intelligence & Audit Logs for Firewall Analysis

Cloud Audit Logs (Admin Activity) record who made changes to firewall rules. Policy Intelligence's Policy Analyzer helps understand the impact of firewall rules by analyzing reachability and effective policies, crucial for security investigations.

  • Admin Activity logs track firewall rule modifications.
  • Policy Analyzer evaluates rule impact and reachability.
  • Together, they provide comprehensive firewall change and impact analysis.

Memory trick: Audit logs show 'who', Policy Analyzer shows 'what' they enable.

More Managing operations questions