Soru

Zorluk: OrtaSecurity Logging, Audit Logs, and Security Command Center

An enterprise organization operates a multi-folder Google Cloud resource hierarchy. To comply with security governance, the organization must aggregate all Admin Activity and Data Access audit logs across all current and future projects in real time into an external SIEM system, while enabling centralized, agentless threat detection across all workloads. Which solution meets these requirements?

  1. Create an organization-level Cloud Logging aggregated sink routing logs to a Pub/Sub topic connected to the SIEM, and enable Security Command Center Premium with Event Threat Detection.Cevap
  2. B
    Grant the Owner primitive IAM role to a central service account across all projects to pull logs via the Logging API, and rely on standard Cloud Monitoring metric thresholds for threat detection.
  3. C
    Configure Data Access audit logs in each project, relying solely on IAM permission boundaries to prevent unauthorized data exfiltration to external Cloud Storage buckets.
  4. D
    Require application teams to export audit logs to Cloud Storage encrypted with Customer-Supplied Encryption Keys (CSEK), and schedule batch transfers using Storage Transfer Service.

Cevap

Create an organization-level Cloud Logging aggregated sink routing logs to a Pub/Sub topic connected to the SIEM, and enable Security Command Center Premium with Event Threat Detection.
Creating an aggregated log sink at the Google Cloud Organization level ensures all audit logs across all present and future projects within the resource hierarchy are centralized. Exporting these logs to a Pub/Sub topic allows real-time ingestion by an external SIEM system. Combining this with Security Command Center Premium Event Threat Detection enables agentless, real-time threat monitoring directly from audit log streams.

Adım Adım Çözüm

1
Determine the optimal strategy for organization-wide real-time audit log export.
Configure an aggregated log sink at the Google Cloud Organization resource level targeting a Pub/Sub topic.
Organization-level aggregated sinks automatically include all child folders and projects, ensuring new projects are covered without manual configuration, while Pub/Sub enables real-time streaming to the SIEM.
2
Select an agentless threat detection mechanism across the cloud footprint.
Enable Security Command Center (SCC) Premium Event Threat Detection.
Event Threat Detection continuously analyzes Cloud Audit Logs streams to uncover suspicious activity (such as malware or unauthorized data access) without requiring agents inside compute instances.

Anahtar Kavram

Centralized Log Aggregation and Agentless Threat Detection using Cloud Logging and Security Command Center
Bu soruyu puanla