Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise wants to establish a comprehensive auditing and monitoring framework for user-managed service account keys across hundreds of projects in its Google Cloud organization. The security operations team has defined the following technical requirements:
Which combination of Google Cloud services and configurations should the security team deploy to satisfy these requirements?
Enable VPC Flow Logs across all subnets to capture service account authentication signatures; analyze Cloud SQL insights for dormant keys; and configure Data Access audit logs on all storage buckets to trigger Cloud Monitoring alerts upon key generation.
Configure Cloud Data Loss Prevention (Sensitive Data Protection) inspection scans on all Cloud Storage buckets; use Web Security Scanner to detect unused credentials; and set up an IAM Conditions policy to automatically expire keys after 90 days.
Deploy Network Analyzer across a multi-project metrics scope to identify aged keys; configure Firewall Rules Logging to detect unused keys; and use Security Command Center to block key generation via automated Cloud Functions.
Query Cloud Asset Inventory for iam.googleapis.com/ServiceAccountKey assets to assess key inventory and age; leverage IAM Policy Intelligence service account key insights to detect unused keys; and configure an organization-level aggregated Cloud Logging sink filtering for google.iam.admin.v1.CreateServiceAccountKey Admin Activity logs connected to Cloud Monitoring and Pub/Sub alerting.
Enable VPC Flow Logs across all subnets to capture service account authentication signatures; analyze Cloud SQL insights for dormant keys; and configure Data Access audit logs on all storage buckets to trigger Cloud Monitoring alerts upon key generation.
Configure Cloud Data Loss Prevention (Sensitive Data Protection) inspection scans on all Cloud Storage buckets; use Web Security Scanner to detect unused credentials; and set up an IAM Conditions policy to automatically expire keys after 90 days.
Deploy Network Analyzer across a multi-project metrics scope to identify aged keys; configure Firewall Rules Logging to detect unused keys; and use Security Command Center to block key generation via automated Cloud Functions.
Query Cloud Asset Inventory for iam.googleapis.com/ServiceAccountKey assets to assess key inventory and age; leverage IAM Policy Intelligence service account key insights to detect unused keys; and configure an organization-level aggregated Cloud Logging sink filtering for google.iam.admin.v1.CreateServiceAccountKey Admin Activity logs connected to Cloud Monitoring and Pub/Sub alerting.
This architecture combines Cloud Asset Inventory, Policy Intelligence (IAM key insights/recommenders), and Cloud Logging aggregated sinks with Cloud Monitoring to establish full lifecycle visibility, inactivity detection, and real-time detection of user-managed service account key creation across an entire organization.
iam.googleapis.com/ServiceAccountKey reveals all existing user-managed keys, their associated service accounts, parent projects, and creation timestamps (validAfterTime).cloudaudit.googleapis.com/activity logs across all child folders and projects. Filtering for protoPayload.methodName="google.iam.admin.v1.CreateServiceAccountKey" captures all key creation events instantly and routes them to a Pub/Sub topic and Cloud Monitoring log-based alert for automated SOC notification.This approach uses Google Cloud-native governance and intelligence tools at the organization hierarchy root, ensuring zero blind spots across newly created or existing projects.