Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 65 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 65

Select 4Google Cloud Platform

Your team discovers that multiple service account private keys have been downloaded by developers to their local machines for testing purposes. To secure and mitigate the usage of service account keys, what steps should you take to address this situation and prevent future risks?

  1. A

    Disable all existing service account keys and generate new ones only when necessary.

  2. B

    Restrict IAM permissions on service accounts to only those who absolutely require them.

  3. C

    Enable the Organization Policy constraint to disable the creation of new service account keys.

  4. D

    Use Cloud KMS to encrypt the service account keys before storing them on developer machines.

  5. E

    Audit existing service account key usage and ensure all active keys are rotated periodically.

Show answer and explanation

Correct answers: A, B, C, E

Explanation

To secure service account keys, it is essential to disable and rotate existing keys, restrict access, and implement policies to prevent the creation of new keys. Additionally, auditing key usage helps identify and mitigate risks. Storing keys on local machines is a poor practice and should be avoided entirely, so encryption of locally stored keys is not a suitable solution.

  • A. Correct.

    Disabling all existing service account keys ensures that previously downloaded keys cannot be used maliciously. New keys should only be generated when absolutely required.

  • B. Correct.

    Restricting IAM permissions prevents unauthorized access to service accounts, reducing the risk of keys being downloaded by unnecessary personnel.

  • C. Correct.

    Enabling the Organization Policy constraint to disable service account key creation ensures that new keys cannot be generated, which is a proactive mitigation step.

  • D. Incorrect.

    Using Cloud KMS to encrypt service account keys on developer machines is not recommended. Keys should not be downloaded to local machines in the first place, making this option invalid.

  • E. Correct.

    Auditing service account key usage and ensuring periodic rotation of active keys is a best practice to detect and reduce the risk of key compromise.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam