Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 62 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 62

Select 3Google Cloud Platform

Your organization uses Google Cloud and has several service accounts with keys that are used by external systems for automation. A recent security audit flagged the improper management of service account keys as a critical vulnerability. What actions should you take to secure and mitigate the usage of these keys?

  1. A

    Rotate the service account keys regularly and implement automated key rotation.

  2. B

    Disable all unused and unnecessary service account keys.

  3. C

    Store service account keys in a publicly accessible storage bucket for backup purposes.

  4. D

    Use IAM roles to grant permissions to service accounts instead of directly using keys where possible.

  5. E

    Restrict the usage of service account keys to only trusted IP ranges.

Show answer and explanation

Correct answers: A, B, D

Explanation

Properly securing, auditing, and mitigating the usage of service account keys is critical to maintaining security in Google Cloud. Regular key rotation, disabling unused keys, and avoiding excessive reliance on keys by leveraging IAM roles are essential practices. Storing keys in publicly accessible locations exposes sensitive data to potential attackers, violating security best practices.

  • A. Correct.

    Regularly rotating service account keys reduces the risk of keys being compromised and provides a standard security practice for key management.

  • B. Correct.

    Disabling unused or unnecessary service account keys minimizes the attack surface and reduces the risk of unauthorized access.

  • C. Incorrect.

    Storing service account keys in a publicly accessible location is a security risk and violates best practices. Keys should always be stored securely using tools like Secret Manager.

  • D. Correct.

    Using IAM roles to grant permissions avoids the need to distribute and manage service account keys directly, reducing the risk of key leakage and misuse.

  • E. Incorrect.

    Restricting the usage of service account keys to trusted IP ranges is not a native feature of Google Cloud and is not an effective means of securing keys. Instead, focus should be on proper key lifecycle management and minimizing key usage.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam