Professional Cloud Security EngineerConfiguring access within a cloud solution environmentMedium

A security analyst is investigating a potential compromise. They need to determine which user or service account was responsible for deleting a critical Cloud Storage bucket. The audit trail must be immutable and provide details such as the identity, timestamp, and affected resource. Which Google Cloud logging service should the analyst consult?

  1. ACloud Logging Policy Denied logs
  2. BCloud Logging Data Access logs
  3. CCloud Audit Logs System Event logs
  4. DCloud Logging Admin Activity logs
Show answer & explanation

Correct answer: D. Cloud Logging Admin Activity logs

Admin Activity logs record administrative operations that modify the configuration or metadata of Google Cloud resources, such as creating or deleting resources. Deleting a Cloud Storage bucket is an administrative action, making Admin Activity logs the correct source for this audit.

Why the other options are wrong

  • A. Policy Denied logs would record attempts to violate policies, but not the successful deletion of a resource itself.
  • B. Data Access logs record API calls that read or write user-provided data, but not administrative actions like deleting a bucket (unless specifically configured for this, which isn't the primary use case).
  • C. System Event logs are generated by Google systems to help with debugging and are not directly used for auditing user/service account actions.

Cloud Audit Logs: Admin Activity

Admin Activity logs record API calls or other administrative actions that modify the configuration or metadata of resources, always enabled and immutable.

  • Tracks resource creation/deletion/modification.
  • Always enabled by default.
  • Immutable audit trail for compliance.

Memory trick: Admin logs track who changed what.

More Configuring access within a cloud solution environment questions