CHFI Application, Email and Cloud Forensics Practice Question
In a Google Cloud Platform (GCP) environment, a forensic investigator needs to determine who deleted a Cloud Storage bucket and when. Which log type should be queried to obtain this information?
⚠ Common exam trap
EC-Council CHFI often tests the distinction between data-plane logs (access logs) and control-plane logs (admin activity audit logs), and the trap here is that candidates mistakenly choose Cloud Storage access logs because they associate 'deletion' with bucket-level activity, not realizing that bucket deletion is a configuration change logged only in Admin Activity audit logs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cloud Audit Logs (Admin Activity)
Cloud Audit Logs (Admin Activity) in GCP record all API calls that modify the configuration or metadata of resources, including the deletion of a Cloud Storage bucket. These logs capture the identity of the principal who performed the action, the timestamp, and the specific operation (e.g., `storage.buckets.delete`), making them the authoritative source for answering who deleted a bucket and when.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cloud Monitoring metrics
Why it's wrong here
Cloud Monitoring provides only operational telemetry—metric time-series, uptime checks, and alerting policies—not a record of who performed an action or what API method was invoked. It may show a sudden drop in bucket metrics after deletion, but it cannot identify the actor, the exact delete request, or reconstruct the event for forensics. Monitoring data is supplementary anomaly detection, not an authoritative audit trail.
- ✗
VPC flow logs
Why it's wrong here
VPC flow logs capture layer-3/4 network traffic metadata—source/destination IPs, ports, protocols, and packet counts—for traffic passing through VPC subnets. A bucket deletion is a control-plane API call over HTTPS, which flow logs do not parse or log semantically; they neither record the API method nor the authenticated user identity. At best, flow logs might show an encrypted connection to storage.googleapis.com, but they cannot prove that a bucket deletion occurred or by whom.
- ✗
Cloud Storage access logs
Why it's wrong here
Cloud Storage access logs are data-plane logs that record individual object requests (e.g., GETs, PUTs, DELETEs of objects) and are typically enabled for data access auditing. Bucket deletion, however, is a bucket-level administrative operation executed via the Cloud Storage API, not an object-level data access event. Because access logs are scoped to requests on objects within the bucket, they will not contain a record of the bucket's own deletion—that operation is logged only in Cloud Audit Logs as an Admin Activity event.
- ✓
Cloud Audit Logs (Admin Activity)
Why this is correct
Cloud Audit Logs (Admin Activity) are the correct source because they capture all control-plane API calls that modify configuration or metadata, including the storage.buckets.delete method that removes a Cloud Storage bucket. These administrative audit logs record the authenticated principal, the API method, the target resource, the request metadata, and the response status, giving investigators a complete attribution trail for the deletion. This audit log is enabled by default in GCP for all projects, making it the authoritative forensic evidence for bucket deletion events.
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.