Professional Cloud Security EngineerConfiguring access within a cloud solution environmentMedium
A security team needs to audit all administrative activities performed by project owners across their organization's Google Cloud environment. Specifically, they want to track when a project owner creates or deletes a service account, or grants/revokes IAM roles to any principal. The audit logs must be retained for at least one year and be easily queryable for security investigations. Which type of audit log should the security engineer focus on, and how can they ensure long-term retention?
- AData Access logs; route them to Cloud Storage with a retention policy.
- BPolicy Denied logs; enable them at the folder level and store in Cloud SQL.
- CAdmin Activity logs; route them to Cloud Logging and then to BigQuery for analysis.
- DSystem Event logs; export them to a custom SIEM solution.
Show answer & explanationAnswer & explanation
Correct answer: C. Admin Activity logs; route them to Cloud Logging and then to BigQuery for analysis.
Admin Activity logs record administrative actions that modify the configuration or metadata of resources, such as creating service accounts or modifying IAM policies. Routing these logs to Cloud Logging and then exporting them to BigQuery ensures long-term retention and powerful querying capabilities for security investigations.
Why the other options are wrong
- A. Data Access logs record API calls that read or modify user-provided data, not administrative actions on resources. Storing in Cloud Storage is possible but BigQuery is better for querying.
- B. There isn't a standard 'Policy Denied' log type for this purpose. Cloud SQL is not the primary long-term log storage and analysis solution for audit logs.
- D. System Event logs record Google Cloud system events (e.g., VM migrations), not user-initiated administrative actions. Exporting to a SIEM is an option, but the log type is wrong.
Google Cloud Admin Activity Logs
Audit logs that record API calls or other actions that modify the configuration or metadata of resources, such as creating VMs, setting IAM policies, or modifying network configurations.
- Always enabled by default and cannot be disabled.
- Includes operations like 'create', 'update', 'delete'.
- Crucial for auditing administrative changes and security incidents.
Memory trick: Admin acts, Data flows, System hums, Policy protects.