nerdexam
Google

PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #133

Which Google Cloud log source is MOST critical for detecting unauthorized IAM role changes?

The correct answer is B. Cloud Audit Logs - Admin Activity. Admin Activity logs record IAM policy changes and administrative actions, even if logging is otherwise restricted.

Security Monitoring and Threat Detection

Question

Which Google Cloud log source is MOST critical for detecting unauthorized IAM role changes?

Options

  • AVPC Flow Logs
  • BCloud Audit Logs - Admin Activity
  • CCloud DNS logs
  • DFirewall Rules logs

How the community answered

(32 responses)
  • A
    9% (3)
  • B
    75% (24)
  • C
    3% (1)
  • D
    13% (4)

Explanation

Admin Activity logs record IAM policy changes and administrative actions, even if logging is otherwise restricted.

Topics

#Cloud Audit Logs#Admin Activity logs#IAM monitoring#log sources

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER Practice