Google Associate Cloud EngineerSetting up a cloud solution environmentMedium
A company is migrating its on-premises applications to Google Cloud. They have a strict security policy requiring all network traffic to be logged and audited. They need to configure their Google Cloud projects to ensure that all administrative activities and data access events are captured. Which service should they enable and configure?
- ACloud Trace
- BCloud Monitoring
- CCloud Audit Logs
- DCloud Logging
Show answer & explanationAnswer & explanation
Correct answer: C. Cloud Audit Logs
Cloud Audit Logs specifically capture administrative activities and data access events across Google Cloud services, which is essential for security auditing and compliance requirements.
Why the other options are wrong
- A. Cloud Trace is for distributed tracing of application requests, not system-wide audit logging.
- B. Cloud Monitoring focuses on metrics and uptime, not audit trails.
- D. Cloud Logging is a general-purpose logging service, but Cloud Audit Logs is the specific subset designed for auditability and compliance.
Cloud Audit Logs
Cloud Audit Logs record administrative activities, data access events, and system events across Google Cloud services for security, auditing, and compliance.
- Automatically enabled for Admin Activity logs.
- Data Access logs require explicit configuration.
- Integrates with Cloud Logging for storage and export.
Memory trick: When you need to audit, look for the 'Audit' in the logs.