Professional Cloud Security EngineerConfiguring access within a cloud solution environmentMedium

A security auditor needs to verify that all service accounts created within a specific Google Cloud project adhere to the principle of least privilege. Specifically, they need to identify any service accounts that have been granted the 'roles/editor' role or broader permissions. Which Google Cloud IAM tool or feature should the auditor use to efficiently gather this information?

  1. AExamine Admin Activity Logs to see when roles were granted to service accounts.
  2. BRun `gcloud iam service-accounts describe` for every service account in the project.
  3. CReview the 'IAM' page in the Google Cloud Console for each service account individually.
  4. DUse the Cloud Asset Inventory to export all IAM policies for the project and filter the results.
Show answer & explanation

Correct answer: D. Use the Cloud Asset Inventory to export all IAM policies for the project and filter the results.

Cloud Asset Inventory provides a centralized and comprehensive view of all Google Cloud assets, including their IAM policies. Exporting this data allows for efficient filtering and analysis to identify service accounts with specific roles like 'roles/editor' across the entire project.

Why the other options are wrong

  • A. Admin Activity Logs show *when* roles were granted, but not the current state of all roles for all service accounts at once for an audit of current permissions.
  • B. `gcloud iam service-accounts describe` provides details for a single service account, which is not efficient for auditing many accounts.
  • C. Manually reviewing each service account is time-consuming and inefficient for auditing a large number of accounts.

Cloud Asset Inventory (IAM Auditing)

Cloud Asset Inventory provides a centralized inventory service for Google Cloud assets and their associated metadata, including IAM policies, making it suitable for security auditing and compliance.

  • Centralized view of all cloud assets.
  • Exports IAM policies for analysis.
  • Supports large-scale auditing and compliance checks.

Memory trick: Inventory assets to audit roles efficiently.

More Configuring access within a cloud solution environment questions