Memory hook: Posture finds exposure; telemetry finds activity; response limits harm.
Must remember
Security Command Center centralizes supported posture, vulnerability and threat findings. Security Health Analytics identifies misconfiguration; detectors and custom modules address specific risks. Cloud IDS inspects supported mirrored network traffic. VPC Flow Logs describe sampled flow metadata; they are not a full packet capture. Traffic mirroring has scope, volume and privacy consequences.
Cloud Audit Logs distinguish administrative activity and supported data-access activity. Check which logs are available/enabled, especially data access, and aggregate them to a protected destination with suitable retention. Separate the ability to administer workloads from the ability to erase evidence. Correlate identity, resource, timestamp and deployment context before declaring a finding a confirmed incident.
Harden GKE/Cloud Run workloads, restrict images, scan dependencies and enforce trusted deployment policies. Patch operating systems and dependencies according to exposure and exploitability. A vulnerability finding requires validation, prioritization, remediation and confirmation; a dashboard alone does not close the risk.
Contain incidents with proportionate controls: revoke compromised credentials, isolate workloads, preserve evidence and communicate through the response process. Record actions and timestamps. Changing resources before preserving volatile evidence can hinder investigation, while delaying containment can increase harm; follow the approved playbook and incident authority.
Assured Workloads provides supported compliance-oriented controls. Access Transparency provides visibility into eligible provider access; Access Approval adds approval workflows for eligible access. They are different controls with scope and exceptions. Residency, sovereignty, contractual commitments and audit evidence must be evaluated against the actual workload; a certified provider does not automatically certify the customer’s application.
Review details
Audit recall: Admin Activity records administration, Data Access records supported data reads/writes and related access, System Event records provider-driven resource changes, and Policy Denied records supported denials. Admin Activity/System Event are always written; most Data Access needs enablement, with BigQuery a notable default-enabled exception. Private data-access logs also need appropriate reader permissions.
An aggregated sink can route matching descendant-resource logs to a central destination, provided the sink writer is authorized. Protect sink configuration and destination retention independently from workload ownership. Confirm missing evidence was actually collected before drawing conclusions from an empty query.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Misconfigured cloud resources | SCC posture findings with ownership and remediation. |
| Investigate access to sensitive records | Relevant data-access audit logs and protected evidence. |
| Visibility versus approval of provider access | Access Transparency versus Access Approval. |
Traps
- Flow logs are not complete packet contents.
- Cloud provider compliance does not transfer all customer obligations.
Active recall
1. Posture versus detection?
Exposure/configuration assessment versus evidence of suspicious activity.
2. Why protect aggregated logs separately?
To reduce an attacker’s ability to erase evidence after compromising a workload.
3. Why verify data-access logging?
Availability/default behavior varies; absent logs cannot reconstruct every past access.
4. What is Access Transparency for?
Visibility into eligible Google personnel access.
5. What is Access Approval for?
Configured approval of eligible provider access requests, subject to documented scope and exceptions.