Medium1 markMultiple Choice
Domain 5.3: Viewing audit logsDomain 5.3Audit LogsCloud Logging

GCP ACE · Question 48 · Domain 5.3: Viewing audit logs

You suspect that a user accidentally deleted a critical Compute Engine instance yesterday. You need to verify who performed the deletion and when it happened.

Which type of Cloud Audit Log should you review?

Answer options:

A.

Data Access logs

B.

System Event logs

C.

Admin Activity logs

D.

Access Transparency logs

How to approach this question

Differentiate between the types of Cloud Audit Logs.

Full Answer

C.Admin Activity logs✓ Correct
Cloud Audit Logs are divided into several categories. Admin Activity logs contain log entries for API calls and administrative actions that modify the configuration or metadata of resources (e.g., creating a VM, deleting a bucket, changing IAM policies). These are enabled by default and cannot be disabled.

Common mistakes

Confusing Admin Activity (modifying resources) with Data Access (reading/writing data inside the resource).

Practice the full GCP Associate Cloud Engineer Practice Exam 4

50 questions · hints · full answers · grading

More questions from this exam