← Professional Cloud Security Engineer: controls and evidence
07 / 8 · 45 MIN

Auditing, detection, and response

Build accessible evidence and connect findings to verifiable actions.

Concept and mechanism

Cloud Audit Logs categories have different scopes and defaults. Admin Activity records administrative changes and continues being generated even if the Cloud Logging API is disabled. Data Access covers data operations and needs explicit enablement for services other than BigQuery. Confirm service, operation, project, and configuration present at event time. Query authorization is another dimension: Logs Viewer alone cannot read Data Access in _Default; private-log access needs appropriate permissions and authorized scope. An empty query does not prove no access occurred. It can mean absent collection, incorrect filter, expired retention, or missing permission.

Guided application

In a fictional incident, a SIEM sink is created only after the alert. Look for history still retained at source; new routing does not automatically backfill. Retain evidence and coordinate proportionate containment before deleting suspected resources. Findings also need interpretation: SCC mute does not remediate the resource or remove the finding from documented compliance calculations. Prioritize using exploitation, exposure, criticality, and existing controls. A Binary Authorization attestation is only as useful as its producing criteria and process. For security fixes, exercise compatibility and recovery; if approved temporary mitigation exists, define owner and exit deadline. A cleaner visual state does not demonstrate reduced risk.

IN PRACTICE

Enabling Data Access today improves future evidence but does not reconstruct reads never recorded yesterday.

Common pitfalls

Admin Activity as every read; empty query as no event; sink as backup; mute as remediation.

Related topics: Federation and temporary access · IAM, deny, and inheritance · IAP, WAF, and perimeters

Take this idea with you

Demonstrate collection, access, interpretation, and action as distinct steps.

Create account

Reference: Cloud Audit Logs overview · Current linked guide; edition date unconfirmed (2026-09-30 inspection)