You are part of a security team investigating a compromised service account key. You need to audit which new resources were created by the service account. What should you do?
Shouldn't it be A? The question is about which resources were created by the SA.
B (Admin Activity logs) cannot view this. It is only for user's activity such as create, modify or delete a particular SA.
"Admin Activity audit logs contain log entries for API calls or other administrative actions that modify the configuration or metadata of resources. For example, these logs record when users create VM instances or change Identity and Access Management permissions".
This is exactly what you want to see. What resources were created by the SA?
https://cloud.google.com/logging/docs/audit#admin-activity
Ans B
"B" is for actions that modify the configuration or metadata of resources. For example, these logs record when users create VM instances or change Identity and Access Management permissions.
"A" is only for "user-provided" resource data. Data Access audit logs-- except for BigQuery Data Access audit logs-- "are disabled by default"
To audit which new resources were created by a compromised service account key, you should query Admin Activity logs 1.
Admin Activity logs provide a record of every administrative action taken in your Google Cloud Platform (GCP) project, including the creation of new resources 1. By querying Admin Activity logs, you can identify which new resources were created by the compromised service account key and take appropriate action to secure your environment 1.
You can use the gcloud command-line tool or the Cloud Console to query Admin Activity logs 1. You can filter the logs based on specific criteria, such as time range, user, or resource type 1.
Admin activity logs are always created to log entries for API calls or other actions that modify the configuration or metadata of resources. For example, these logs record when users create VM instances or change Identity and Access Management permissions.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
MohitA
Highly Voted 4 years, 1 month agoFellipo
3 years, 11 months agoownez
4 years, 1 month agoFatCharlie
3 years, 11 months agoAzureDP900
1 year, 12 months agoVicF
Highly Voted 3 years, 6 months agodija123
Most Recent 7 months agoXoxoo
1 year, 1 month agoMeyucho
1 year, 10 months agoAwesomeGCP
2 years agoJoseMaria111
2 years, 1 month agopiyush_1982
2 years, 3 months agocloudprincipal
2 years, 4 months ago[Removed]
3 years, 6 months agoDebasishLowes
3 years, 7 months ago[Removed]
3 years, 12 months ago