Google Associate Cloud EngineerConfiguring access and securityMedium
A new compliance officer has joined your team and needs to review all Identity and Access Management (IAM) policy changes that have occurred across all projects in your Google Cloud organization over the last six months. They need to see who made the changes, what changes were made, and when. Which type of audit log should the compliance officer examine?
- AAdmin Activity logs
- BData Access logs
- CSystem Event logs
- DCloud Audit Logs (all types)
Show answer & explanationAnswer & explanation
Correct answer: A. Admin Activity logs
Admin Activity logs record all API calls and administrative actions that modify the configuration or metadata of Google Cloud resources, including changes to IAM policies. These logs are crucial for auditing and compliance, providing the 'who, what, and when' for policy modifications.
Why the other options are wrong
- B. Data Access logs record operations on user-provided data, not changes to IAM policies.
- C. System Event logs record actions taken by Google systems, not user-initiated IAM policy changes.
- D. While 'Cloud Audit Logs (all types)' would include Admin Activity logs, the most precise and relevant type for IAM policy changes is Admin Activity logs.
IAM Policy Audit Logging
IAM policy audit logging refers to the process of recording changes made to Identity and Access Management policies in Google Cloud.
- Changes are captured in Admin Activity logs.
- Records who made the change, the specific policy modification, and the timestamp.
- Essential for security audits and compliance tracking of access controls.
Memory trick: Admin logs report on the administrators changing the rules.