Professional Cloud Security EngineerConfiguring access within a cloud solution environmentMedium

A security analyst is investigating a potential compromise. They need to determine which user or service account generated a specific API key within a Google Cloud project and when it was created. The analyst has access to Cloud Logging for the project and organization. Where should the analyst look for this information?

  1. AAudit logs within the API Keys service console directly.
  2. BData Access logs for the Cloud Key Management Service (KMS).
  3. CAdmin Activity logs for the Service Usage API or IAM API.
  4. DSystem Event logs for the project.
Show answer & explanation

Correct answer: C. Admin Activity logs for the Service Usage API or IAM API.

Generating an API key is an administrative action that modifies the project's configuration (creating a resource). Such actions are recorded in Admin Activity logs, specifically those for the Service Usage API (which manages API keys) or the IAM API (if the key creation was tied to a service account). These logs will contain details about the principal who performed the action and the timestamp.

Why the other options are wrong

  • A. While the API Keys service console shows existing keys, it doesn't provide a detailed audit trail of *who* created *when* directly within its UI, relying on Cloud Logging for that granular information.
  • B. Data Access logs record operations on user data, not the creation of administrative resources like API keys.
  • D. System Event logs record Google system-level events, not user-initiated administrative actions.

Admin Activity Logs (API Keys)

Cloud Audit Logs that record when API keys are created, deleted, or modified, including the identity of the principal performing the action.

  • Crucial for auditing changes to API key management.
  • Stored in Cloud Logging.
  • Provides 'who', 'what', 'when' for administrative changes.

Memory trick: Admin Activity is the 'ledger' for 'key' operations.

More Configuring access within a cloud solution environment questions