exam questions

Exam Professional Cloud Security Engineer All Questions

View all questions & answers for the Professional Cloud Security Engineer exam

Exam Professional Cloud Security Engineer topic 1 question 86 discussion

Actual exam question from Google's Professional Cloud Security Engineer
Question #: 86
Topic #: 1
[All Professional Cloud Security Engineer Questions]

You are part of a security team investigating a compromised service account key. You need to audit which new resources were created by the service account.
What should you do?

  • A. Query Data Access logs.
  • B. Query Admin Activity logs.
  • C. Query Access Transparency logs.
  • D. Query Stackdriver Monitoring Workspace.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
MohitA
Highly Voted 4 years, 1 month ago
B is the Ans
upvoted 14 times
Fellipo
3 years, 11 months ago
B it's OK
upvoted 4 times
...
ownez
4 years, 1 month ago
Shouldn't it be A? The question is about which resources were created by the SA. B (Admin Activity logs) cannot view this. It is only for user's activity such as create, modify or delete a particular SA.
upvoted 1 times
FatCharlie
3 years, 11 months ago
"Admin Activity audit logs contain log entries for API calls or other administrative actions that modify the configuration or metadata of resources. For example, these logs record when users create VM instances or change Identity and Access Management permissions". This is exactly what you want to see. What resources were created by the SA? https://cloud.google.com/logging/docs/audit#admin-activity
upvoted 10 times
AzureDP900
1 year, 12 months ago
B is right . Agree with your explanation
upvoted 2 times
...
...
...
...
VicF
Highly Voted 3 years, 6 months ago
Ans B "B" is for actions that modify the configuration or metadata of resources. For example, these logs record when users create VM instances or change Identity and Access Management permissions. "A" is only for "user-provided" resource data. Data Access audit logs-- except for BigQuery Data Access audit logs-- "are disabled by default"
upvoted 6 times
...
dija123
Most Recent 7 months ago
Selected Answer: B
Agree with B
upvoted 1 times
...
Xoxoo
1 year, 1 month ago
Selected Answer: B
To audit which new resources were created by a compromised service account key, you should query Admin Activity logs 1. Admin Activity logs provide a record of every administrative action taken in your Google Cloud Platform (GCP) project, including the creation of new resources 1. By querying Admin Activity logs, you can identify which new resources were created by the compromised service account key and take appropriate action to secure your environment 1. You can use the gcloud command-line tool or the Cloud Console to query Admin Activity logs 1. You can filter the logs based on specific criteria, such as time range, user, or resource type 1.
upvoted 2 times
...
Meyucho
1 year, 10 months ago
Selected Answer: B
B - Audit logs. They have all the API calls that creates, modify or destroy resources. https://cloud.google.com/logging/docs/audit#admin-activity
upvoted 2 times
...
AwesomeGCP
2 years ago
Selected Answer: B
B. Query Admin Activity logs.
upvoted 3 times
...
JoseMaria111
2 years, 1 month ago
Admin activity log records resources changes. B is correct
upvoted 2 times
...
piyush_1982
2 years, 3 months ago
Selected Answer: B
Admin activity logs are always created to log entries for API calls or other actions that modify the configuration or metadata of resources. For example, these logs record when users create VM instances or change Identity and Access Management permissions.
upvoted 2 times
...
cloudprincipal
2 years, 4 months ago
Selected Answer: B
Admin activity logs contain all GCP API calls. So this is where the service account activity will show up
upvoted 2 times
...
[Removed]
3 years, 6 months ago
I support B, https://cloud.google.com/iam/docs/audit-logging says IAM logs write into admin log
upvoted 4 times
...
DebasishLowes
3 years, 7 months ago
Ans : B
upvoted 3 times
...
[Removed]
3 years, 12 months ago
Ans - B
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago