A security administrator needs to investigate which user modified IAM permissions and created new Compute Engine instances within a project. The administrator requires access to log entries that record administrative actions and configuration changes. Which Cloud Audit Logs category provides this record and is enabled by default across all Google Cloud projects?
- Admin Activity audit logsAnswer
- BData Access audit logs
- CCustomer-Managed Encryption Key (CMEK) audit logs
- DPrimitive IAM Viewer event logs
Answer
Admin Activity audit logs contain entries for API calls or administrative actions that modify resource configurations or metadata, and they are always enabled by default.
Admin Activity audit logs record API calls or administrative actions that alter the configuration or metadata of Google Cloud resources. These logs are generated automatically and enabled by default across all projects, making them the correct choice for auditing IAM and instance creation operations.
Step-by-Step Solution
Key Concept
Cloud Audit Logs categories and default enablement behavior