A security auditor needs to verify that all API calls made by administrators within a Google Cloud organization are logged and immutable for at least one year. They also require that these logs are easily queryable for auditing purposes. Which combination of Cloud Logging features should be used?
- ACloud Logging sink to a BigQuery dataset with a table expiration set to one year.
- BCloud Logging default _Default log bucket with log views for easy querying.
- CCloud Logging sink to a Cloud Storage bucket with bucket-level retention policy and object immutability enabled.
- DCloud Logging default _Required log bucket with a custom retention policy set to one year.
Show answer & explanationAnswer & explanation
Correct answer: D. Cloud Logging default _Required log bucket with a custom retention policy set to one year.
Admin Activity logs are automatically routed to the `_Required` log bucket, which cannot be disabled and has a default retention of 400 days (over one year). This ensures immutability and compliance. Custom retention policies can be applied to extend this if needed, and logs in buckets are easily queryable via Log Explorer.
Why the other options are wrong
- A. A BigQuery sink for logs is great for complex analytics, but for simple immutability and auditability of Admin Activity logs, the `_Required` bucket is purpose-built and sufficient.
- B. The `_Default` log bucket receives Data Access and System Event logs (if enabled), not primarily Admin Activity logs. Log views help querying but don't address the immutability or specific log type requirement.
- C. While a Cloud Storage sink can provide immutability, the `_Required` bucket already handles Admin Activity logs, making this an unnecessary additional step for this specific log type.
Cloud Logging _Required Log Bucket
The `_Required` log bucket is a special Cloud Logging bucket that automatically receives all Admin Activity logs and System Event logs for a project, folder, or organization. It cannot be disabled, its retention can only be increased (default 400 days), and it ensures log immutability for compliance.
- Automatically receives Admin Activity and System Event logs.
- Cannot be disabled, ensuring critical audit trails.
- Logs are immutable and retained for at least 400 days by default.
Memory trick: Required bucket secures the audit trail.