ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 110 - Professional Cloud Security Engineer discussion

Report
Export

Your Security team believes that a former employee of your company gained unauthorized access to Google Cloud resources some time in the past 2 months by using a service account key. You need to confirm the unauthorized access and determine the user activity. What should you do?

A.
Use Security Health Analytics to determine user activity.
Answers
A.
Use Security Health Analytics to determine user activity.
B.
Use the Cloud Monitoring console to filter audit logs by user.
Answers
B.
Use the Cloud Monitoring console to filter audit logs by user.
C.
Use the Cloud Data Loss Prevention API to query logs in Cloud Storage.
Answers
C.
Use the Cloud Data Loss Prevention API to query logs in Cloud Storage.
D.
Use the Logs Explorer to search for user activity.
Answers
D.
Use the Logs Explorer to search for user activity.
Suggested answer: D

Explanation:

We use audit logs by searching the Service Account and checking activities in the past 2 months. (the user identity will not be seen since he used the SA identity but we can make correlations based on ip address, working hour, etc. )

asked 18/09/2024
Isidre Piguillem
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first