Professional Cloud Security EngineerConfiguring access within a cloud solution environmentMedium
A security analyst is investigating a potential compromise. They need to determine which user or service account was responsible for deleting a critical Cloud Storage bucket. The audit trail must be immutable and provide details such as the identity, timestamp, and affected resource. Which Google Cloud logging service should the analyst consult?
- ACloud Logging Policy Denied logs
- BCloud Logging Data Access logs
- CCloud Audit Logs System Event logs
- DCloud Logging Admin Activity logs
Show answer & explanationAnswer & explanation
Correct answer: D. Cloud Logging Admin Activity logs
Admin Activity logs record administrative operations that modify the configuration or metadata of Google Cloud resources, such as creating or deleting resources. Deleting a Cloud Storage bucket is an administrative action, making Admin Activity logs the correct source for this audit.
Why the other options are wrong
- A. Policy Denied logs would record attempts to violate policies, but not the successful deletion of a resource itself.
- B. Data Access logs record API calls that read or write user-provided data, but not administrative actions like deleting a bucket (unless specifically configured for this, which isn't the primary use case).
- C. System Event logs are generated by Google systems to help with debugging and are not directly used for auditing user/service account actions.
Cloud Audit Logs: Admin Activity
Admin Activity logs record API calls or other administrative actions that modify the configuration or metadata of resources, always enabled and immutable.
- Tracks resource creation/deletion/modification.
- Always enabled by default.
- Immutable audit trail for compliance.
Memory trick: Admin logs track who changed what.