Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise wants to establish a comprehensive auditing and monitoring framework for user-managed service account keys across hundreds of projects in its Google Cloud organization. The security operations team has defined the following technical requirements:
Which combination of Google Cloud services and configurations should the security team deploy to satisfy these requirements?
This architecture combines Cloud Asset Inventory, Policy Intelligence (IAM key insights/recommenders), and Cloud Logging aggregated sinks with Cloud Monitoring to establish full lifecycle visibility, inactivity detection, and real-time detection of user-managed service account key creation across an entire organization.
iam.googleapis.com/ServiceAccountKey reveals all existing user-managed keys, their associated service accounts, parent projects, and creation timestamps (validAfterTime).cloudaudit.googleapis.com/activity logs across all child folders and projects. Filtering for protoPayload.methodName="google.iam.admin.v1.CreateServiceAccountKey" captures all key creation events instantly and routes them to a Pub/Sub topic and Cloud Monitoring log-based alert for automated SOC notification.This approach uses Google Cloud-native governance and intelligence tools at the organization hierarchy root, ensuring zero blind spots across newly created or existing projects.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.