Courseiva

Google PCA Manage and provision cloud infrastructure Practice Question

An organization needs to audit all changes to network firewall rules in a GCP project. Which service should be used to capture these changes?

⚠ Common exam trap

Many candidates confuse Cloud Logging (which is a general log storage and analysis platform) with Cloud Audit Logs (which is a specific type of log that records administrative actions), leading them to pick A instead of C.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cloud Audit Logs

Cloud Audit Logs (specifically Admin Activity audit logs) record all API calls that modify the configuration or metadata of resources, including changes to firewall rules. When a firewall rule is created, updated, or deleted, an audit log entry is automatically generated with details such as the user, timestamp, and the change made. This makes Cloud Audit Logs the correct service for auditing changes to network firewall rules in a GCP project.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cloud Logging

    Why it's wrong here

    Cloud Logging records audit entries for API-driven configuration changes, but firewall rule modifications surface through Admin Activity audit logs, which must be routed to a log sink for retention and review; Cloud Logging alone is the raw capture layer, not the audit destination. It is the right tool for querying and exporting log data generally.

  • ✗

    Cloud Monitoring

    Why it's wrong here

    Cloud Monitoring collects metrics, uptime checks and alerting policies on resource performance; it does not record who changed a firewall rule or when. It tempts because it surfaces anomalies and dashboards, but configuration-change auditing requires Admin Activity audit logs, which Monitoring neither stores nor exposes as change records.

  • ✓

    Cloud Audit Logs

    Why this is correct

    Cloud Audit Logs records Admin Activity and Data Access entries, including firewall rule insertions, updates and deletions in a GCP project. It is the native service that captures these configuration changes for audit, satisfying the requirement to track all firewall rule modifications.

  • ✗

    VPC Flow Logs

    Why it's wrong here

    VPC Flow Logs capture sampled IP traffic metadata for connections through subnets, recording source, destination and disposition, not administrative API calls that alter firewall rules. It appeals for network forensics and traffic analysis, but change auditing needs Admin Activity audit logs, which Flow Logs never generate.

Go deeper

Related to this question

About these practice questions

This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.