Google
PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #133
Which Google Cloud log source is MOST critical for detecting unauthorized IAM role changes?
The correct answer is B. Cloud Audit Logs - Admin Activity. Admin Activity logs record IAM policy changes and administrative actions, even if logging is otherwise restricted.
Security Monitoring and Threat Detection
Question
Which Google Cloud log source is MOST critical for detecting unauthorized IAM role changes?
Options
- AVPC Flow Logs
- BCloud Audit Logs - Admin Activity
- CCloud DNS logs
- DFirewall Rules logs
How the community answered
(32 responses)- A9% (3)
- B75% (24)
- C3% (1)
- D13% (4)
Explanation
Admin Activity logs record IAM policy changes and administrative actions, even if logging is otherwise restricted.
Topics
#Cloud Audit Logs#Admin Activity logs#IAM monitoring#log sources
Community Discussion
No community discussion yet for this question.