nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #318

A security audit uncovered several inconsistencies in your project's Identity and Access Management (IAM) configuration. Some service accounts have overly permissive roles, and a few external…

The correct answer is C. Use Cloud Audit Logs. Create log export sinks to send these logs to a security information and. This approach allows you to monitor and analyze IAM changes comprehensively, ensuring that you can detect and respond to any security issues effectively https://cloud.google.com/iam/docs/audit-logging

Submitted by tarun92· Apr 18, 2026Ensuring compliance

Question

A security audit uncovered several inconsistencies in your project's Identity and Access Management (IAM) configuration. Some service accounts have overly permissive roles, and a few external collaborators have more access than necessary. You need to gain detailed visibility into changes to IAM policies, user activity, service account behavior, and access to sensitive projects. What should you do?

Options

  • AConfigure Google Cloud Functions to be triggered by changes to IAM policies. Analyze changes
  • BEnable the metrics explorer in Cloud Monitoring to follow the service account authentication
  • CUse Cloud Audit Logs. Create log export sinks to send these logs to a security information and
  • DDeploy the OS Config Management agent to your VMs. Use OS Config Management to create

How the community answered

(36 responses)
  • A
    11% (4)
  • B
    3% (1)
  • C
    83% (30)
  • D
    3% (1)

Explanation

This approach allows you to monitor and analyze IAM changes comprehensively, ensuring that you can detect and respond to any security issues effectively https://cloud.google.com/iam/docs/audit-logging

Topics

#Cloud Audit Logs#IAM auditing#Security monitoring#SIEM integration

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice