A security engineer is investigating a potential insider threat scenario where a compromised service account might be making unauthorized API calls. They need to quickly identify all API calls made by a specific service account across all projects in the organization, including calls that failed due to permission denied errors, for the past 30 days. Which Cloud Logging feature or product should the engineer primarily utilize?
- ACloud Logging Logs Explorer with Data Access logs and Admin Activity logs enabled.
- BSecurity Command Center Event Threat Detection findings.
- CCloud Monitoring Logs Explorer
- DChronicle Security Operations for unified log analysis.
Show answer & explanationAnswer & explanation
Correct answer: A. Cloud Logging Logs Explorer with Data Access logs and Admin Activity logs enabled.
To identify all API calls, including failed ones, both Admin Activity logs (for administrative actions) and Data Access logs (for data access, often including failed attempts) are crucial. Cloud Logging's Logs Explorer allows filtering across all projects for a specific service account within the last 30 days, making it the most direct and efficient tool for this specific investigation.
Why the other options are wrong
- B. Event Threat Detection focuses on *already identified* threats and anomalies. The engineer is *investigating* to find such calls, not just reviewing pre-detected findings. It wouldn't provide the raw, unfiltered API call data needed for a comprehensive investigation.
- C. Cloud Monitoring Logs Explorer is the same as Cloud Logging Logs Explorer, but focusing solely on 'Cloud Monitoring' might imply metrics, which is not the primary need here. While Logs Explorer is correct, the scope of logs (Admin + Data Access) is critical.
- D. While Chronicle can do this, it's an overkill for a focused investigation within Google Cloud logs for a specific principal. Cloud Logging's native Logs Explorer is more direct and efficient for this scope.
Logs Explorer for API Call Investigation
Cloud Logging's Logs Explorer enables detailed filtering and analysis of Admin Activity and Data Access logs to trace all API calls, including failed ones, by specific principals across an organization.
- Uses Cloud Logging Logs Explorer
- Requires both Admin Activity and Data Access logs
- Allows filtering by `principalEmail` and time ranges
Memory trick: Explore all logs for that service account, even the failed calls!