Instiq
Chapter 4 · Managing operations·v1.0.0·Updated 6/15/2026·~16 min

What's changed: Created Professional Cloud Security Engineer Chapter 4 (Domain 4 "Operations": CVE scanning in CI/CD (Artifact Analysis)/Binary Authorization (GKE/Cloud Run)/image hardening-VM patch management/CSPM-custom org policies-Security Health Analytics custom modules; network logs (Cloud NGFW/VPC flow logs/Packet Mirroring/Cloud IDS/Log Analytics), logging strategy, incident response, secure log access, external SIEM export, Cloud Audit Logs/data access logs, log sinks/aggregated sinks, Security Command Center).

4.2Logging, monitoring, and threat detection

Key points

Understand configuring/analyzing network logs (Cloud NGFW, VPC flow logs, Packet Mirroring, Cloud IDS, Log Analytics), an effective logging strategy, incident logging/monitoring/response/remediation, secure access to logs, exporting logs to external security systems, configuring/analyzing Cloud Audit Logs and data access logs, log exports (log sinks, aggregated sinks), and configuring/monitoring Security Command Center.

Detection and response come from "collect the right logs, find threats, and store/forward them securely." Center the design on audit logs and the security platform.

4.2.1Audit logs and log export

Record "who did what, when" with Cloud Audit Logs. Admin Activity logs are on by default; enable sensitive Data Access logs explicitly. For long-term retention, analysis, and SIEM, export with log sinks to BigQuery/Cloud Storage/Pub/Sub, and use an aggregated sink to collect across an org/folder at once. Export to external security systems (SIEM/SOAR) via Pub/Sub. Prevent tampering/deletion by minimizing access to logs and protecting their destinations. Map "collect org-wide logs at once = aggregated sink" and "audit trail = Cloud Audit Logs (enable Data Access)."

Continue reading — free sign-up

You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.