nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #129

Your Security team believes that a former employee of your company gained unauthorized access to Google Cloud resources some time in the past 2 months by using a service account key. You need to…

The correct answer is D. Use the Logs Explorer to search for user activity. We use audit logs by searching the Service Account and checking activities in the past 2 months. (the user identity will not be seen since he used the SA identity but we can make correlations based on ip address, working hour, etc. )

Submitted by certguy· Apr 18, 2026Managing operations within a cloud solution environment

Question

Your Security team believes that a former employee of your company gained unauthorized access to Google Cloud resources some time in the past 2 months by using a service account key. You need to confirm the unauthorized access and determine the user activity. What should you do?

Options

  • AUse Security Health Analytics to determine user activity.
  • BUse the Cloud Monitoring console to filter audit logs by user.
  • CUse the Cloud Data Loss Prevention API to query logs in Cloud Storage.
  • DUse the Logs Explorer to search for user activity.

How the community answered

(26 responses)
  • A
    12% (3)
  • B
    8% (2)
  • C
    4% (1)
  • D
    77% (20)

Explanation

We use audit logs by searching the Service Account and checking activities in the past 2 months. (the user identity will not be seen since he used the SA identity but we can make correlations based on ip address, working hour, etc. )

Topics

#Unauthorized access detection#Service account key security#Log analysis#Cloud Logging

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice