Professional Cloud Security EngineerManaging operationsMedium
A financial institution is migrating its on-premises applications to Google Cloud. They need to ensure that all administrative activities performed by their Google Cloud administrators are immutably recorded and retained for seven years to meet regulatory compliance requirements. The logs must not be modifiable or deletable by any user, including organization administrators. Which Google Cloud Logging feature should the institution configure to meet these requirements?
- ASet up a Pub/Sub topic to receive Admin Activity logs and then stream them to a third-party SIEM with long-term archiving capabilities.
- BEnable the _Required Log Buckets feature at the organization level and configure a retention policy of seven years with a lock.
- CConfigure a custom log sink to export Admin Activity logs to a Cloud Storage bucket with object versioning enabled.
- DCreate a custom log bucket for Admin Activity logs, apply a retention policy of seven years, and restrict access using IAM conditions.
Show answer & explanationAnswer & explanation
Correct answer: B. Enable the _Required Log Buckets feature at the organization level and configure a retention policy of seven years with a lock.
The _Required Log Buckets feature, when configured with a lock, provides immutable and non-deletable storage for Admin Activity and Data Access logs, which is crucial for regulatory compliance. This feature specifically prevents even organization administrators from deleting the logs before the retention period expires.
Why the other options are wrong
- A. Exporting to a third-party SIEM can provide long-term archiving, but the question specifically asks for a Google Cloud Logging feature to ensure the logs are immutably recorded and retained within Google Cloud, and the immutability guarantee for the original logs is not met by this approach.
- C. Cloud Storage object versioning helps with accidental deletion but does not provide the same level of immutability and non-deletability as a locked _Required Log Bucket against malicious administrative actions.
- D. While a custom log bucket allows for retention policies and IAM restrictions, it does not offer the same level of immutability and protection against deletion by organization administrators as a locked _Required Log Bucket.
_Required Log Buckets with Lock
A Google Cloud Logging feature that automatically routes all Admin Activity and Data Access logs to a dedicated, unmodifiable log bucket, ensuring immutable storage for compliance.
- Automatically collects Admin Activity and Data Access logs.
- Configurable at the organization level.
- Retention policies can be applied and locked, preventing deletion even by organization administrators.
- Essential for strict regulatory compliance requirements.
Memory trick: Required logs locked tight, no one can delete, day or night.