nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #20

You are part of a security team investigating a compromised service account key. You need to audit which new resources were created by the service account. What should you do?

The correct answer is B. Query Admin Activity logs. Admin activity logs are always created to log entries for API calls or other actions that modify the configuration or metadata of resources. For example, these logs record when users create VM instances or change Identity and Access Management permissions…

Submitted by daniela_cl· Apr 18, 2026Managing operations within a cloud solution environment

Question

You are part of a security team investigating a compromised service account key. You need to audit which new resources were created by the service account. What should you do?

Options

  • AQuery Data Access logs.
  • BQuery Admin Activity logs.
  • CQuery Access Transparency logs.
  • DQuery Stackdriver Monitoring Workspace.

How the community answered

(26 responses)
  • B
    92% (24)
  • C
    4% (1)
  • D
    4% (1)

Explanation

Admin activity logs are always created to log entries for API calls or other actions that modify the configuration or metadata of resources. For example, these logs record when users create VM instances or change Identity and Access Management permissions. https://cloud.google.com/logging/docs/audit#admin-activity

Topics

#Cloud Logging#Admin Activity logs#Service account security#Resource auditing

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice