Google Associate Cloud EngineerConfiguring access and securityEasy
A security team needs to monitor all administrative actions performed by users and service accounts across their Google Cloud organization to ensure compliance with internal security policies. They specifically want to see who performed which action and when. Which type of audit log should they focus on for this requirement?
- AAdmin Activity logs
- BData Access logs
- CPolicy Denied logs
- DSystem Event logs
Show answer & explanationAnswer & explanation
Correct answer: A. Admin Activity logs
Admin Activity logs record administrative actions that modify the configuration or metadata of Google Cloud resources. These logs are crucial for security and compliance, as they show who did what and when, which directly addresses the security team's requirement.
Why the other options are wrong
- B. Data Access logs record API calls that read or modify user-provided data, not administrative actions.
- C. Policy Denied logs are not a standard category of Google Cloud audit logs; policy denials would typically appear within other log types if configured.
- D. System Event logs record actions taken by Google systems, not directly user or service account administrative actions.
Admin Activity Logs
Admin Activity logs record API calls or other actions that modify the configuration or metadata of resources.
- Always enabled by default, cannot be disabled.
- Crucial for auditing changes to resource configurations.
- Includes who performed the action, which resource, and when.
Memory trick: Admin logs watch the admins, data logs watch the data.