How to Gain Visibility into IAM Policy Changes and User Activity on GCP?
A security audit uncovered several inconsistencies in your project's Identity and Access Management (IAM) configuration. Some service accounts have overly permissive roles, and a few external collaborators have more access than necessary. You need to gain detailed visibility into changes to IAM policies, user activity, service account behavior, and access to sensitive projects. What should you do?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests knowledge of GCP's native auditing mechanism versus generic monitoring tools, where candidates often confuse Cloud Monitoring metrics with immutable audit trails.
Cloud Audit Logs provide comprehensive tracking of administrative and data access activities across Google Cloud projects. This guide establishes why exporting these logs to a SIEM via sinks is the correct architectural choice for security monitoring.
Option A is frequently chosen because it involves automation and alerts, but Cloud Functions and the Policy Simulator lack the centralized, immutable logging required for comprehensive security audits.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Cloud Audit Logs are Google Cloud’s native, immutable logging service designed specifically to track administrative and data access activities. By creating log export sinks, you can automatically route these records to an external SIEM, enabling cross-source correlation and long-term retention. This architecture satisfies the requirement for detailed visibility into IAM policy modifications, service account behavior, and sensitive project access.Why the Other Options Are Wrong
Option A relies on Cloud Functions and the Policy Simulator, which are useful for reactive testing but lack the centralized, continuous logging capability needed for comprehensive audits. Option B focuses on Cloud Monitoring metrics, which track performance thresholds and uptime rather than granular identity and access events. Option D deploys an OS-level patching agent, which is entirely unrelated to managing or auditing cloud-native IAM configurations.Community Comment Notes
Learners consistently recognize that Cloud Audit Logs provide the broadest coverage of API calls and identity events compared to other tooling. As Pime13 noted, "This approach allows you to monitor and analyze IAM changes comprehensively," highlighting the need for centralized tracking. Several users confirmed that routing these logs to a SIEM via export sinks enables the necessary correlation capabilities for modern security operations.Official Reference
Exam Strategy
Match keywords like 'visibility', 'changes to IAM policies', and 'access to sensitive projects' directly to Cloud Audit Logs, which are purpose-built for immutable tracking. Always prioritize centralized log aggregation via export sinks when SIEM integration or long-term compliance is mentioned.
Frequently Asked Questions
Why not use Cloud Monitoring metrics instead of Audit Logs?
Metrics track performance and availability thresholds, whereas Audit Logs capture immutable administrative and data access events required for compliance.
Can I view IAM policy changes directly in the Google Cloud Console?
Yes, under Logging > Explorer, but exporting to a SIEM via sinks is necessary for centralized correlation and long-term retention.