Professional Cloud Security EngineerManaging operationsEasy

A security engineer is tasked with ensuring that all administrative activities performed by project owners in a Google Cloud organization are logged and retained for seven years for compliance purposes. The organization has multiple projects, and new projects are created frequently. Which Google Cloud service should be configured to meet this requirement efficiently?

  1. ACloud Monitoring to create custom metrics for administrative activities.
  2. BCloud Logging with log sinks configured at the organization level.
  3. CCloud Audit Logs directly configured within each individual project.
  4. DSecurity Command Center to detect administrative activity anomalies.
Show answer & explanation

Correct answer: B. Cloud Logging with log sinks configured at the organization level.

Cloud Logging, specifically with log sinks configured at the organization level, is the most efficient and scalable way to centralize and retain administrative activity logs across multiple projects for compliance. This ensures all current and future projects are covered automatically.

Why the other options are wrong

  • A. Cloud Monitoring is for collecting and visualizing metrics, not for long-term log retention for compliance.
  • C. Configuring Cloud Audit Logs in each individual project is not efficient or scalable for an organization with many and frequently created projects.
  • D. Security Command Center is for threat detection and vulnerability management, not the primary service for log retention.

Cloud Logging Log Sinks

Cloud Logging log sinks allow you to route logs from Cloud Logging to supported destinations like Cloud Storage, BigQuery, or Pub/Sub for storage, analysis, or integration with other systems. Sinks can be configured at the project, folder, or organization level.

  • Centralizes logs from multiple sources.
  • Supports various destinations for different use cases.
  • Organization-level sinks apply to all projects within the organization.

Memory trick: Logs funnel into storage for compliance.

More Managing operations questions