Courseiva
Google Cloud SecurityhardMultiple ChoiceObjective-mapped

Cloud Digital Leader Google Cloud Security Practice Question

A DevOps engineer wants to audit all actions performed by Google personnel on their customer data stored in Cloud Storage. They need to review logs that show access by Google employees and the reason for access. Which logging feature should they enable?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Access Transparency

Access Transparency provides logs of Google personnel accessing customer data. It shows the time, reason, and data accessed. Cloud Audit Logs track actions performed by users and services within the customer's project, not Google personnel. VPC Flow Logs are for network flows. Cloud Logging is the general platform but does not specifically capture Google personnel access without Access Transparency.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Cloud Audit Logs

    Why it's wrong here

    Cloud Audit Logs record actions performed by customer principals — IAM users, service accounts, and identities — through the Cloud Auditing API, but they explicitly exclude actions taken by Google employees or subprocessors on customer data. Admin activity and data access audit logs show who in the customer's own tenant called a Google Cloud API, not any internal Google personnel access. Therefore, they are the wrong tool for auditing Google personnel.

  • Cloud Logging

    Why it's wrong here

    Cloud Logging is the scalable, real-time logging infrastructure used to ingest, store, and analyze all log types, including Cloud Audit Logs and Access Transparency logs. However, Cloud Logging by itself is only a storage and querying layer; it does not generate the logs that capture Google personnel access. Without enabling Access Transparency, Cloud Logging has no record of internal Google actions, so it is not a sufficient answer for this audit need.

  • Access Transparency

    Why this is correct

    Access Transparency is the correct feature because it provides real-time logs of every action taken by Google personnel (and certain subprocessors) when accessing customer content, including reads, writes, and administrative operations. It complements Cloud Audit Logs by covering the 'Google-side' of the shared responsibility model, which no other logging option addresses. It must be explicitly enabled on the organization, folder, or project, and it works only for a defined set of Google Cloud services.

  • VPC Flow Logs

    Why it's wrong here

    VPC Flow Logs capture IP traffic metadata — source and destination addresses, ports, protocols, and packet/byte counts — for network flows between VMs, on-premises resources, and other endpoints in a VPC. They do not log API-level actions, human identity, or data-plane operations like reading a Cloud Storage object or querying a database, and they certainly cannot see Google personnel accessing internal systems. Thus, they are irrelevant to auditing actions by Google staff.

About these practice questions

Courseiva writes every GCDL question from scratch — 829 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.