Google ACE Configuring Access and Security Practice Question
A security engineer wants to audit all attempts to access a specific Cloud Storage bucket, including successful and failed read requests. Which THREE steps should they take? (Choose THREE)
⚠ Common exam trap
ACE often tests the distinction between Admin Activity logs (always on, control-plane) and Data Access logs (opt-in, data-plane) — candidates who pick 'enable Admin Activity logs' miss that reads are data-plane events.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Data Access audit logs for the Cloud Storage service.
Option B is correct because Cloud Storage read requests (both successful and failed) are recorded only in Data Access audit logs, which are disabled by default and must be explicitly enabled for the Cloud Storage service. Option C is correct because once Data Access logs are enabled, they can be queried in Log Explorer using filters such as resource.type="gcs_bucket" and the bucket name to isolate the relevant read attempts. Option D is correct because the auditor needs the roles/logging.viewer role (or equivalent) on the project to view and filter those audit logs in Log Explorer. Option A is not needed because BigQuery sinks are for exporting/analyzing logs, not for auditing access attempts directly, and Admin Activity logs do not capture data reads. Option E is incorrect because Admin Activity audit logs are always enabled and record administrative/config changes, not successful or failed object read requests.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a log sink to BigQuery for the bucket's admin activity logs.
Why it's wrong here
Creating a log sink to BigQuery for the bucket's admin activity logs is incorrect because a log sink merely exports existing log entries to a destination and does not enable any logging itself. Admin Activity logs, even if exported, record configuration changes like bucket IAM updates or lifecycle changes, not read/write access attempts against objects. To capture audit trails of data access, you must enable Data Access audit logs for Cloud Storage, which is the only way to generate the relevant log entries in the first place.
- ✓
Enable Data Access audit logs for the Cloud Storage service.
Why this is correct
Enabling Data Access audit logs for the Cloud Storage service is correct because these logs specifically record every successful and failed read, write, and metadata operation on objects and buckets. By default, Data Access audit logs are disabled, so they must be explicitly turned on for Cloud Storage for the auditor to capture access attempts. Once enabled, each entry includes the principal, source IP, operation (e.g. storage.objects.get), and timestamp—providing the detailed evidence needed for an audit trail.
- ✓
Use Log Explorer to filter for the bucket's data access logs.
Why this is correct
Using Log Explorer to filter for the bucket's data access logs is correct because Cloud Logging's Log Explorer provides a queryable interface to search, analyze, and view log entries. After data access audit logs are enabled, you can use filters like resource.type="gcs_bucket" and logName="projects/PROJECT_ID/logs/cloudaudit.googleapis.com%2Fdata_access" to isolate bucket access events. This is the essential operational step for the auditor to actually inspect the recorded attempts.
- ✓
Grant the auditor the roles/logging.viewer role on the project.
Why this is correct
Granting the auditor the roles/logging.viewer role on the project is correct because Cloud Logging requires a reader to have an IAM role that grants logging.logEntries.get permission to view log entries. This read-only role allows the auditor to query logs via Log Explorer or the Logging API, including accessing the audit logs that will be generated. For private Data Access audit logs, a more permissive role such as roles/logging.privateLogViewer may be needed in some organizations, but the basic viewer role is a necessary baseline for any log viewing activity.
- ✗
Enable Admin Activity audit logs for the bucket.
Why it's wrong here
Enabling Admin Activity audit logs for the bucket is incorrect because Admin Activity logs capture operational changes to the bucket's configuration, such as creating, deleting, or changing IAM policies, but never capture data access requests like GET or PUT on objects. Since the security engineer wants to audit *attempts to access* the bucket, these logs would miss all object-level reads/writes. Only Data Access audit logs provide that level of detail; Admin Activity logs are enabled by default but serve a completely different purpose.
Go deeper
Related to this question
Learn chapter
Cloud Storage Retention Policies and Locks
Key term
Service
A service is a software component or system that performs a specific function and is available to be used by other programs or users over a network.
Key term
BigQuery
BigQuery is a fully managed, serverless data warehouse on Google Cloud that lets you run fast SQL queries on massive datasets without managing any infrastructure.
About these practice questions
One of 775 original ACE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.