Professional Cloud Security EngineerConfiguring access within a cloud solution environmentMedium

A security engineer is investigating an unusual spike in API calls from a specific service account. They need to determine which user or process was responsible for creating this service account and when it was created. Which Google Cloud logging service should the engineer query?

  1. ACloud Audit Logs - Data Access logs
  2. BCloud Monitoring - Metrics Explorer
  3. CCloud Logging - System Event logs
  4. DCloud Audit Logs - Admin Activity logs
Show answer & explanation

Correct answer: D. Cloud Audit Logs - Admin Activity logs

Admin Activity logs record API calls or other administrative actions that modify the configuration or metadata of resources. Creating a service account is an administrative action, so this information would be found in Admin Activity logs.

Why the other options are wrong

  • A. Data Access logs record API calls that read or modify user-provided data within resources, not administrative actions like creating service accounts.
  • B. Cloud Monitoring's Metrics Explorer focuses on time-series data for resource performance and status, not individual administrative events or who performed them.
  • C. System Event logs are system-generated logs for Google Cloud internal events and resource state changes, not user-initiated administrative actions.

Cloud Audit Logs - Admin Activity

A type of Google Cloud Audit Log that records administrative actions and metadata changes to Google Cloud resources.

  • Always enabled by default and cannot be disabled.
  • Records operations that modify resource configuration or metadata.
  • Includes details like who performed the action, when, and from where.

Memory trick: Admin Activity Alters All A-OK.

More Configuring access within a cloud solution environment questions