An auditor needs to review who accessed objects in Cloud Storage buckets. What should you provide?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable Data Access audit logs for those buckets and query them in Logs Explorer filtered for Cloud Storage..
Why this is the answer
The correct answer is to enable Data Access audit logs and query them in Logs Explorer. Data Access audit logs record API calls that read or modify data within a Google Cloud service, such as object access in Cloud Storage. These logs are crucial for auditing data access. Logs Explorer provides a powerful interface to filter and analyze these logs. Assigning permissions and creating a Data Studio report on Admin Activity audit logs is incorrect because Admin Activity logs record operations that modify the configuration or metadata of resources, not data access. Using Cloud Monitoring to review metrics is also incorrect as Monitoring focuses on performance and health metrics, not individual data access events. Exporting Admin Activity audit logs via the Logs API is incorrect for the same reason as the Data Studio option: Admin Activity logs don't capture the required data access information.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed