Choose two. To create a tamper-evident, organization-wide trail of network configuration changes (firewall rules, router changes, peering), which actions should you take?
Choose an answer
Tap an option to check your answer.
Correct answer: Export Admin Activity audit logs to a protected Cloud Storage bucket with object versioning and CMEK, Stream Admin Activity audit logs into a BigQuery dataset and restrict dataset IAM with logging of access.
Why this is the answer
Admin Activity audit logs record API calls and administrative actions, including network configuration changes like firewall rules and router updates. Exporting these logs to a protected Cloud Storage bucket with object versioning and Customer-Managed Encryption Keys (CMEK) ensures immutability, tamper-evidence, and controlled access. Streaming these logs to BigQuery with restricted IAM and access logging provides a queryable, secure, and auditable history. VPC Flow Logs capture network traffic, not configuration changes. Relying solely on Terraform state snapshots is insufficient as not all changes are made via Terraform, and it lacks the tamper-evident properties of audit logs.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed