Courseiva

Cloud Digital Leader Trust and security with Google Cloud Practice Question

A multinational corporation operates a hybrid cloud environment with on-premises data centers connected to Google Cloud via Dedicated Interconnect. The company uses Cloud Storage to store sensitive financial data and has enabled Cloud Audit Logs for admin activities. Recently, the security team noticed that an unknown actor accessed a bucket containing customer personally identifiable information (PII). The access occurred from an IP address outside the corporate network. The security team suspects that an employee's Google Cloud credentials were compromised. They need to investigate the incident thoroughly and determine the extent of the breach. The company has enabled VPC Flow Logs, but they are not sure how to correlate the audit logs with network flows. They also want to ensure that similar incidents are prevented in the future. What should the security team do first to investigate the incident?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Cloud Logging to analyze Cloud Audit Logs and identify the user who accessed the bucket and the associated context.

The correct first step is option C: use Cloud Logging to analyze Cloud Audit Logs and identify the user who accessed the bucket and the associated context. Cloud Audit Logs record Admin Activity and Data Access events for Cloud Storage, including the principal (user or service account), the bucket/object accessed, the source IP address, and timestamps, which directly supports determining who did what and the extent of the breach. Options A and B are remediation or prevention actions, not investigation steps, and revoking all keys/passwords before scoping the incident could disrupt operations and destroy evidence. Option D focuses on VPC Flow Logs, which show network-level metadata for traffic within VPCs but do not identify the authenticated Cloud Storage principal or the API action taken, so it cannot by itself establish the identity and scope of the bucket access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Immediately revoke all service account keys and reissue them, then reset all user passwords.

    Why it's wrong here

    Revoking keys and resetting passwords destroys forensic evidence and disrupts legitimate access before the breach scope is known. It is tempting as containment, but the question asks what to do first to investigate, so correlating Cloud Audit Logs with VPC Flow Logs must precede credential rotation.

  • ✗

    Enable Cloud IDS to detect similar attacks and block the malicious IP address.

    Why it's wrong here

    Cloud IDS detects intrusions on your VPC networks, but the breach already happened via compromised credentials over the public internet, so it neither investigates past activity nor blocks an external IP. It is tempting because it provides threat detection, yet it would be correct for proactively monitoring live network traffic, not for forensic analysis of an existing incident.

  • ✓

    Use Cloud Logging to analyze Cloud Audit Logs and identify the user who accessed the bucket and the associated context.

    Why this is correct

    Cloud Audit Logs record the authenticated identity, timestamp, source IP and method for each bucket access, so analysing them in Cloud Logging identifies the compromised user and the breach scope. This directly satisfies the requirement to determine who accessed the PII bucket.

  • ✗

    Export VPC Flow Logs to BigQuery and analyze for the attacker's IP address.

    Why it's wrong here

    Exporting VPC Flow Logs to BigQuery analyses network metadata but cannot reveal which identity performed the bucket access, since that detail lives in Cloud Audit Logs. It is tempting for flow correlation, but the first investigative step is querying audit logs for the actor and affected resources.

Go deeper

Related to this question

About these practice questions

One of 848 original GCDL practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.