Courseiva

CHFI Application, Email and Cloud Forensics Practice Question

A cloud forensic investigator is analyzing a GCP audit log entry for a Compute Engine instance. Which THREE fields are essential for identifying the user and operation performed?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

methodName

GCP audit logs include the principal email (authenticationInfo), operation type (methodName), and resource name (resourceName). IP address and user agent may be in requestMetadata but not always in every log entry.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    requestMetadata.callerIp

    Why it's wrong here

    requestMetadata.callerIp records the source IP address from the network layer. This value is frequently unreliable for user attribution because it may reflect a NAT gateway, proxy, or a Google Cloud VPN tunnel endpoint rather than the actual end user. Moreover, for service accounts or workloads using internal IPs or Private Google Access the field can be absent or meaningless, and IP addresses are often ephemeral. Thus, while useful for network context, it is not a core field for identifying the user or determining the operation being investigated.

  • ✓

    methodName

    Why this is correct

    methodName is the fully qualified name of the API method invoked, such as v1.compute.instances.delete. This field is essential because it directly answers the investigator's primary question of what operation was performed on the resource. In Cloud Audit Logs, the methodName is what allows filtering for specific actions (e.g., deleting instances, modifying IAM policies) and is indispensable for reconstructing the sequence of events during an incident.

  • ✓

    resourceName

    Why this is correct

    resourceName is the canonical path of the GCP resource that was affected by the operation, for example projects/my-project/zones/us-central1-a/instances/my-instance. This field is crucial for scoping the investigation and understanding the blast radius of an attacker's actions. It complements methodName by identifying the specific target, enabling correlation across multiple log entries for the same resource and supporting impact assessments.

  • ✗

    requestMetadata.userAgent

    Why it's wrong here

    requestMetadata.userAgent contains the client application string, such as the gcloud CLI version or a browser fingerprint. This field is not essential for user identification because user-agent strings are trivially spoofed and vary based on client software, SDK versions, and proxies; they do not authenticate or uniquely bind to a principal. Even when present, it adds minimal evidentiary value compared to explicit authentication data, and its absence does not impede the investigation of the core action taken.

  • ✓

    authenticationInfo.principalEmail

    Why this is correct

    authenticationInfo.principalEmail is the email address of the authenticated principal — a human user, service account, or Google Workspace identity — that performed the operation. This is the authoritative user identification field in GCP audit logs, derived from the authenticated identity via IAM mechanisms. It is essential because it directly links the log entry to the accountable entity, even when other metadata like IP or user agent is ambiguous, and it supports evidence for access reviews and forensic attribution.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.