Soru

Zorluk: KolaySecurity Logging, Audit Logs, and Security Command Center

An organization is establishing baseline security logging policies across their Google Cloud projects. Which of the following statements accurately describe default behavior and capabilities of Google Cloud Audit Logs? (Select TWO)

  1. Admin Activity audit logs are enabled by default for all Google Cloud services and do not incur log ingestion costs.Cevap
  2. Data Access audit logs are disabled by default for most services because they record high-volume data read and write operations.Cevap
  3. C
    Assigning primitive IAM roles such as Editor ensures that service accounts cannot alter security log sinks.
  4. D
    Relying strictly on IAM role bindings is sufficient to prevent authorized users from exfiltrating audit log data to external locations.

Cevap

Admin Activity audit logs are enabled by default at no cost, and Data Access audit logs are disabled by default for most GCP services to avoid excessive log ingestion.
Admin Activity audit logs are enabled automatically across all GCP resources without additional ingestion charges. Conversely, Data Access audit logs are disabled by default (except BigQuery) to manage data ingestion volume and log storage expenses.

Adım Adım Çözüm

1
Evaluate default state of Admin Activity audit logs
Admin Activity logs record administrative configuration changes and are always enabled by default free of charge.
Google Cloud mandates Admin Activity logging across all GCP services to ensure foundational administrative accountability.
2
Evaluate default state of Data Access audit logs
Data Access logs are disabled by default for most services (with BigQuery being an exception).
Data Access API operations generate extremely high volumes of events, so enabling them requires explicit user configuration.

Anahtar Kavram

Cloud Audit Log Types and Default Configuration
Bu soruyu puanla