How to Gain Visibility into IAM Policy Changes and User Activity on GCP?

Cloud Logging & Security Auditing
Answer Correct answer: C — Configure Cloud Audit Logs and create log export sinks to forward IAM and access records to a SIEM for comprehensive security correlation.

A security audit uncovered several inconsistencies in your project's Identity and Access Management (IAM) configuration. Some service accounts have overly permissive roles, and a few external collaborators have more access than necessary. You need to gain detailed visibility into changes to IAM policies, user activity, service account behavior, and access to sensitive projects. What should you do?

  1. Configure Google Cloud Functions to be triggered by changes to IAM policies. Analyze changes by using the policy simulator, send alerts upon risky modifications, and store event details.
  2. Enable the metrics explorer in Cloud Monitoring to follow the service account authentication events and build alerts linked on it.
  3. Use Cloud Audit Logs. Create log export sinks to send these logs to a security information and event management (SIEM) solution for correlation with other event sources. Correct Answer
  4. Deploy the OS Config Management agent to your VMs. Use OS Config Management to create patch management jobs and monitor system modifications.

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests knowledge of GCP's native auditing mechanism versus generic monitoring tools, where candidates often confuse Cloud Monitoring metrics with immutable audit trails.

Cloud Audit Logs provide comprehensive tracking of administrative and data access activities across Google Cloud projects. This guide establishes why exporting these logs to a SIEM via sinks is the correct architectural choice for security monitoring.

Option A is frequently chosen because it involves automation and alerts, but Cloud Functions and the Policy Simulator lack the centralized, immutable logging required for comprehensive security audits.

Community Discussion (3 comments)

Pime13 👍 1 Selected: C
This approach allows you to monitor and analyze IAM changes comprehensively, ensuring that you can detect and respond to any security issues effectively https://cloud.google.com/iam/docs/audit-logging
json4u 👍 1 Selected: C
It's C
abdelrahman89 👍 3
C - Comprehensive Logging: Cloud Audit Logs capture a wide range of activities, including IAM policy changes, user logins, API calls, and resource access. This provides a comprehensive view of your organization's IAM activity. Log Export: By creating log export sinks, you can send Cloud Audit Logs to a SIEM solution, where they can be correlated with other event sources to identify potential security threats. Detailed Analysis: SIEM solutions can provide advanced analytics and reporting capabilities, allowing you to analyze IAM changes, detect anomalies, and identify potential security risks.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Cloud Audit Logs are Google Cloud’s native, immutable logging service designed specifically to track administrative and data access activities. By creating log export sinks, you can automatically route these records to an external SIEM, enabling cross-source correlation and long-term retention. This architecture satisfies the requirement for detailed visibility into IAM policy modifications, service account behavior, and sensitive project access.

Why the Other Options Are Wrong

Option A relies on Cloud Functions and the Policy Simulator, which are useful for reactive testing but lack the centralized, continuous logging capability needed for comprehensive audits. Option B focuses on Cloud Monitoring metrics, which track performance thresholds and uptime rather than granular identity and access events. Option D deploys an OS-level patching agent, which is entirely unrelated to managing or auditing cloud-native IAM configurations.

Community Comment Notes

Learners consistently recognize that Cloud Audit Logs provide the broadest coverage of API calls and identity events compared to other tooling. As Pime13 noted, "This approach allows you to monitor and analyze IAM changes comprehensively," highlighting the need for centralized tracking. Several users confirmed that routing these logs to a SIEM via export sinks enables the necessary correlation capabilities for modern security operations.

Official Reference

Exam Strategy

Match keywords like 'visibility', 'changes to IAM policies', and 'access to sensitive projects' directly to Cloud Audit Logs, which are purpose-built for immutable tracking. Always prioritize centralized log aggregation via export sinks when SIEM integration or long-term compliance is mentioned.

Frequently Asked Questions

Why not use Cloud Monitoring metrics instead of Audit Logs?

Metrics track performance and availability thresholds, whereas Audit Logs capture immutable administrative and data access events required for compliance.

Can I view IAM policy changes directly in the Google Cloud Console?

Yes, under Logging > Explorer, but exporting to a SIEM via sinks is necessary for centralized correlation and long-term retention.

Related Analysis

← Back to PCSE Study Guide