Google PCA Manage and provision cloud infrastructure Practice Question
An organization needs to audit all changes to network firewall rules in a GCP project. Which service should be used to capture these changes?
⚠ Common exam trap
Many candidates confuse Cloud Logging (which is a general log storage and analysis platform) with Cloud Audit Logs (which is a specific type of log that records administrative actions), leading them to pick A instead of C.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cloud Audit Logs
Cloud Audit Logs (specifically Admin Activity audit logs) record all API calls that modify the configuration or metadata of resources, including changes to firewall rules. When a firewall rule is created, updated, or deleted, an audit log entry is automatically generated with details such as the user, timestamp, and the change made. This makes Cloud Audit Logs the correct service for auditing changes to network firewall rules in a GCP project.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cloud Logging
Why it's wrong here
Cloud Logging records audit entries for API-driven configuration changes, but firewall rule modifications surface through Admin Activity audit logs, which must be routed to a log sink for retention and review; Cloud Logging alone is the raw capture layer, not the audit destination. It is the right tool for querying and exporting log data generally.
- ✗
Cloud Monitoring
Why it's wrong here
Cloud Monitoring collects metrics, uptime checks and alerting policies on resource performance; it does not record who changed a firewall rule or when. It tempts because it surfaces anomalies and dashboards, but configuration-change auditing requires Admin Activity audit logs, which Monitoring neither stores nor exposes as change records.
- ✓
Cloud Audit Logs
Why this is correct
Cloud Audit Logs records Admin Activity and Data Access entries, including firewall rule insertions, updates and deletions in a GCP project. It is the native service that captures these configuration changes for audit, satisfying the requirement to track all firewall rule modifications.
- ✗
VPC Flow Logs
Why it's wrong here
VPC Flow Logs capture sampled IP traffic metadata for connections through subnets, recording source, destination and disposition, not administrative API calls that alter firewall rules. It appeals for network forensics and traffic analysis, but change auditing needs Admin Activity audit logs, which Flow Logs never generate.
Go deeper
Related to this question
Learn chapter
Google Cloud Resource Hierarchy and Organization
Key term
Firewall
A firewall is a network security system that monitors and controls incoming and outgoing traffic based on predetermined security rules to protect trusted internal networks from untrusted external networks.
Key term
Project
A project is a temporary endeavor with a defined beginning and end, undertaken to create a unique product, service, or result, managed through specific processes in IT environments.
About these practice questions
This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.