Google Associate Cloud EngineerConfiguring access and securityEasy
A security auditor needs to review all administrative activities performed on a critical Google Cloud project, specifically focusing on who created, updated, or deleted resources. Which type of audit log should the auditor primarily examine in Cloud Logging?
- AData Access logs
- BSystem Event logs
- CPolicy Denied logs
- DAdmin Activity logs
Show answer & explanationAnswer & explanation
Correct answer: D. Admin Activity logs
Admin Activity logs record API calls or other administrative actions that modify the configuration or metadata of resources. This directly addresses the auditor's need to see who created, updated, or deleted resources.
Why the other options are wrong
- A. Data Access logs record API calls that read or write user-provided data within a project, not administrative changes.
- B. System Event logs record actions taken by Google Cloud systems, not direct user/admin actions.
- C. Policy Denied logs are not a standard log type in Cloud Logging; access denials are typically found within Admin Activity or Data Access logs.
Admin Activity Logs
Audit logs that record API calls or other actions that modify the configuration or metadata of resources within a Google Cloud project.
- Always enabled by default and cannot be disabled.
- Includes operations like creating VMs, updating IAM policies, deleting storage buckets.
- Helps track administrative changes and maintain security posture.
Memory trick: Admin acts, data flows, system events, and policy denies tell the cloud's stories.