A security team wants to receive alerts when a user attempts to grant the 'roles/owner' role to a member outside of the organization's domain. Which log filter should they use to create a log-based metric?
This filter catches IAM policy changes where members are not from the allowed domain.
Why this answer
It uses the Admin Activity audit log type, which captures IAM policy changes, and filters for the SetIamPolicy method on the cloudresourcemanager service. The condition NOT protoPayload.request.policy.bindings: member: "example.com" ensures alerts are triggered only when the owner role is granted to a member outside the organization's domain, matching the security requirement exactly.
Exam trap
In the Google PCA exam, the distinction between Admin Activity logs (for configuration changes like IAM) and Data Access logs (for data reads) is often tested. Candidates mistakenly choose Data Access logs because they associate IAM with 'access control' rather than administrative operations.
How to eliminate wrong answers
Option B is wrong because Data Access logs record read operations on resource data, not IAM policy modifications; SetIamPolicy is an administrative write operation and appears only in Admin Activity logs. Option C is wrong because it filters on compute.instances.setServiceAccount, which changes the service account attached to a VM instance, not the IAM policy granting the owner role to a user. Option D is wrong because System Event logs track Google Cloud system actions (e.g., maintenance events), not user-driven IAM policy changes, and the filter for response.status.code=7 (PERMISSION_DENIED) would only catch failed attempts, not successful grants.