Google PCA Design for security and compliance Practice Question
A company wants to ensure that all access to their Cloud Storage bucket is logged for compliance purposes. Which type of audit log should they enable?
⚠ Common exam trap
Candidates often confuse Admin Activity logs with Data Access logs, thinking that Admin Activity logs cover data access operations, but they only record configuration changes; Data Access logs are needed for actual data access auditing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data Access audit logs
Data Access audit logs (Option B) are required to log every API call that reads, writes, or deletes data in a Cloud Storage bucket, such as object GETs and PUTs. Admin Activity logs only record configuration changes, not data access, so they would not capture the read/write operations needed for compliance logging.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Admin Activity audit logs
Why it's wrong here
Admin Activity audit logs capture configuration and metadata changes, such as bucket creation or IAM policy edits, not object reads or writes. They would be right for tracking administrative changes, but the stem demands logging of all data access, which Data Access logs record.
- ✓
Data Access audit logs
Why this is correct
Data Access audit logs record read and write operations on Cloud Storage objects, capturing who accessed bucket data and when. This satisfies the compliance requirement to log all access, unlike Admin Activity logs which only cover configuration changes.
- ✗
System Event audit logs
Why it's wrong here
System Event audit logs record Google-initiated infrastructure operations, such as live migration or automatic restart of resources, not user or application requests to a bucket. They fit diagnosing platform-side events, but cannot evidence who accessed stored objects for compliance.
- ✗
Access Transparency logs
Why it's wrong here
Access Transparency logs record Google personnel actions on your data, not end-user or application access to a bucket. They suit compliance auditing of Google support staff interventions, so they miss the requirement to log every read and write against the bucket itself.
Go deeper
Related to this question
Learn chapter
Security Best Practices and Compliance
Key term
Data
Data is raw, unprocessed information, like numbers, words, or measurements, that can be stored, processed, and analyzed by computers.
Key term
Cloud storage
Cloud storage is a service that lets you save data on remote servers accessed over the internet instead of on your computer's hard drive.
About these practice questions
Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.