An external auditor needs permissions to review Audit Logs and Data Access logs. Which IAM assignment and guidance should you provide?
Choose an answer
Tap an option to check your answer.
Correct answer: Assign roles/logging.privateLogViewer and instruct the auditor to also review logs for Cloud IAM policy changes..
Why this is the answer
The roles/logging.privateLogViewer role provides read-only access to all logs, including Audit Logs and Data Access logs, which is precisely what an external auditor needs. This role grants the logging.privateLogEntries.list permission, allowing them to view log entries. Additionally, reviewing logs for Cloud IAM policy changes is crucial for an auditor to understand who has access to what and when those permissions were modified, ensuring a comprehensive security review. Exporting logs to Cloud Storage (options A and C) is unnecessary and potentially less secure for a direct review by an auditor, as it creates a separate copy. While logging.privateLogEntries.list is the core permission, roles/logging.privateLogViewer is a predefined role that encapsulates this and other necessary permissions for log viewing, making it the most appropriate and convenient choice over a custom role (options C and D) for this common use case.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed