More Info:

Ensure that Cloud DNS has logging enabled.

Risk Level

Low

Address

Operational Maturity, Reliability, Security

Compliance Standards

CISGCP, CBP

Triage and Remediation

Remediation

To remediate the misconfiguration of GCP DNS not having logging enabled, you can follow the below steps using the GCP console:

  1. Open the GCP console and navigate to the Cloud DNS page.
  2. Select the DNS zone that needs to have logging enabled.
  3. Click on the “Edit” button at the top of the page.
  4. In the “Logging” section, select the checkbox for “Log DNS queries”.
  5. Choose the destination for the logs. You can either select “Logs Explorer” or “Cloud Storage”.
  6. If you choose “Cloud Storage”, provide the bucket name and folder path where the logs will be stored.
  7. Click on the “Save” button to save the changes.

Once logging is enabled, DNS queries made to the DNS zone will be logged and can be viewed in the selected destination. This will help in identifying any potential security threats and troubleshooting DNS issues.

Additional Reading: