QuestionQ342

Managing operations

As part of your organization’s zero-trust strategy, you use Identity-Aware Proxy (IAP) to secure multiple applications. You need to ingest logs into a Security Information and Event Management (SIEM) system so that you receive alerts about possible intrusions.

Which logs should you analyze?

  • A Data Access audit logs
  • B Policy Denied audit logs
  • C Cloud Identity user log events
  • D Admin Activity audit logs
Explanation

IAP records authorized and unauthorized requests to protected resources in Data Access audit logs. These logs contain useful intrusion-detection details, including the authenticated principal when present, caller IP address, requested resource and URL, and whether IAP granted the requested access.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!