Tarnwell Games protects its analytics datasets with a VPC Service Controls perimeter. After a contractor's laptop was compromised, the SOC wants Google Security Operations (formerly Chronicle) to show every request the perimeter blocked, so that repeated exfiltration attempts can be correlated with identity and endpoint telemetry. Direct ingestion still uses its default export filter. Which log source should you prioritize?
- A.
VPC Flow Logs for the contractor subnets, which record connections to Google APIs.
- B.
Policy Denied audit logs, added to the direct ingestion export filter for the organization.
- C.
Admin Activity audit logs, which the default export filter already sends for every perimeter change.
- D.
BigQuery Data Access audit logs, which record each query that runs against the protected datasets.
Show answer
Answer: B
Requests blocked by VPC Service Controls are written as Policy Denied audit logs, which direct ingestion into Google Security Operations (formerly Chronicle) supports but its default filter does not send.
- A. Flow logs show addresses and ports; they carry no API method, resource or policy decision that shows what was blocked.
- B. VPC Service Controls writes blocked requests to Policy Denied audit logs, a supported direct ingestion log that the default filter does not include.
- C. Admin Activity logs record configuration changes such as edits to the perimeter, not the requests that the perimeter refused.
- D. Perimeter refusals are written as Policy Denied entries, not Data Access entries, so this source misses the blocked attempts.
