Google
PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #20
You are part of a security team investigating a compromised service account key. You need to audit which new resources were created by the service account. What should you do?
The correct answer is B. Query Admin Activity logs. Admin activity logs are always created to log entries for API calls or other actions that modify the configuration or metadata of resources. For example, these logs record when users create VM instances or change Identity and Access Management permissions…
Submitted by daniela_cl· Apr 18, 2026Managing operations within a cloud solution environment
Question
You are part of a security team investigating a compromised service account key. You need to audit which new resources were created by the service account. What should you do?
Options
- AQuery Data Access logs.
- BQuery Admin Activity logs.
- CQuery Access Transparency logs.
- DQuery Stackdriver Monitoring Workspace.
How the community answered
(26 responses)- B92% (24)
- C4% (1)
- D4% (1)
Explanation
Admin activity logs are always created to log entries for API calls or other actions that modify the configuration or metadata of resources. For example, these logs record when users create VM instances or change Identity and Access Management permissions. https://cloud.google.com/logging/docs/audit#admin-activity
Topics
#Cloud Logging#Admin Activity logs#Service account security#Resource auditing
Community Discussion
No community discussion yet for this question.