Soru

Zorluk: KolayViewing and Analyzing Cloud Audit Logs

A cloud security engineer needs to review Data Access audit logs in Google Cloud Logging to inspect user activity on Cloud Storage objects. Which predefined IAM role must be granted to the security engineer to view these specific logs?

  1. Private Logs Viewer (roles/logging.privateLogViewer)Cevap
  2. B
    Logs Viewer (roles/logging.viewer)
  3. C
    Project Owner (roles/owner)
  4. D
    Organization Administrator (roles/resourcemanager.organizationAdmin)

Cevap

Grant the Private Logs Viewer (roles/logging.privateLogViewer) role.
Data Access audit logs record API calls that create, modify, or read user-provided resource data. Because these logs can expose sensitive resource contents, Google Cloud restricts access to users with the Private Logs Viewer (roles/logging.privateLogViewer) role or specific logging admin permissions.

Adım Adım Çözüm

1
Identify the log type mentioned in the requirement.
The requirement specifies Data Access audit logs.
Data Access audit logs contain detailed resource access data and require elevated log viewing permissions.
2
Select the minimum necessary predefined IAM role for reading Data Access audit logs.
The Private Logs Viewer (roles/logging.privateLogViewer) role allows viewing Data Access audit logs.
The standard Logs Viewer role omits access to Data Access audit logs to protect sensitive resource data.

Anahtar Kavram

Cloud Audit Logs Access Controls and IAM Roles
Tahmini Süre:45s
Bu soruyu puanla