QuestionQ14

Implementing observability practices and troubleshooting issues

Your company’s security team requires read-only access to Data Access audit logs in the _Required bucket. You want to grant the required permissions to the security team according to the principle of least privilege and Google-recommended practices. What should you do?

Explanation

The Private Logs Viewer role (roles/logging.privateLogViewer) grants read-only access to Data Access audit logs, whereas Logs Viewer does not. Granting that role to a group containing the security team follows Google Cloud IAM guidance to manage shared access through groups instead of individual user grants.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!