Google Associate Cloud EngineerConfiguring access and securityMedium
A compliance team needs to regularly review IAM policy changes across all projects in a Google Cloud organization. Specifically, they need to know when IAM policies are created, updated, or deleted. Which type of audit log, collected at the organization level, should they monitor?
- ASystem Event logs
- BData Access logs
- CAdmin Activity logs
- DPolicy Denied logs
Show answer & explanationAnswer & explanation
Correct answer: C. Admin Activity logs
Admin Activity logs record all administrative actions, including changes to IAM policies (e.g., `setIamPolicy` calls). Monitoring these logs at the organization level will capture all such changes across projects.
Why the other options are wrong
- A. System Event logs track actions by Google systems, not direct user/admin changes to IAM policies.
- B. Data Access logs track reads/writes of user data, not IAM policy modifications.
- D. Policy Denied logs are not a standard log type; access denials are found within other log types.
IAM Policy Audit Logging
The process of recording and reviewing changes to Identity and Access Management policies within Google Cloud, primarily through Admin Activity logs.
- IAM policy changes are recorded as `setIamPolicy` calls in Admin Activity logs.
- These logs are always enabled and cannot be disabled.
- Crucial for security, compliance, and auditing access controls.
Memory trick: Admin Activity logs are the official record of all IAM policy changes, clear for all compliance stages.