Professional Cloud Security EngineerConfiguring access within a cloud solution environmentMedium
A security analyst is investigating a potential compromise. They need to determine which user or service account generated a specific API key within a Google Cloud project and when it was created. The analyst has access to Cloud Logging for the project and organization. Where should the analyst look for this information?
- AAudit logs within the API Keys service console directly.
- BData Access logs for the Cloud Key Management Service (KMS).
- CAdmin Activity logs for the Service Usage API or IAM API.
- DSystem Event logs for the project.
Show answer & explanationAnswer & explanation
Correct answer: C. Admin Activity logs for the Service Usage API or IAM API.
Generating an API key is an administrative action that modifies the project's configuration (creating a resource). Such actions are recorded in Admin Activity logs, specifically those for the Service Usage API (which manages API keys) or the IAM API (if the key creation was tied to a service account). These logs will contain details about the principal who performed the action and the timestamp.
Why the other options are wrong
- A. While the API Keys service console shows existing keys, it doesn't provide a detailed audit trail of *who* created *when* directly within its UI, relying on Cloud Logging for that granular information.
- B. Data Access logs record operations on user data, not the creation of administrative resources like API keys.
- D. System Event logs record Google system-level events, not user-initiated administrative actions.
Admin Activity Logs (API Keys)
Cloud Audit Logs that record when API keys are created, deleted, or modified, including the identity of the principal performing the action.
- Crucial for auditing changes to API key management.
- Stored in Cloud Logging.
- Provides 'who', 'what', 'when' for administrative changes.
Memory trick: Admin Activity is the 'ledger' for 'key' operations.