Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise security engineer is hardening identity governance for a production Google Cloud environment. A security audit reveals that several Compute Engine virtual machines (VMs) are utilizing the Compute Engine default service account (PROJECT_NUMBER-compute@developer.gserviceaccount.com) with the Editor role (roles/editor). Additionally, multiple legacy workloads are being decommissioned, and the operations team plans to immediately delete their associated service accounts.
Which strategy should the security engineer implement to remediate the VM identities and manage the decommissioning lifecycle according to Google Cloud best practices?
Provision dedicated, single-purpose user-managed service accounts with least-privilege roles for the VMs, and disable the decommissioned service accounts for an observation period before deleting them.
Attach the Google APIs Service Agent to the Compute Engine instances, and delete decommissioned service accounts immediately after revoking their access scopes.
Modify the Compute Engine Service Agent roles to grant custom permissions, and use IAM deny policies to disable decommissioned service accounts indefinitely without deleting them.
Recreate the default Compute Engine service account with minimal IAM roles, and immediately delete decommissioned service accounts because recreating an account with the same email restores its prior IAM bindings.
Provision dedicated, single-purpose user-managed service accounts with least-privilege roles for the VMs, and disable the decommissioned service accounts for an observation period before deleting them.
User-managed service accounts are custom identities created and managed by administrators within a project to provide workload-specific authentication and authorization. Managing the service account lifecycle by disabling unused accounts before permanently deleting them is a recommended security control that prevents operational disruption while mitigating lateral movement and privilege escalation risks.
roles/editor role.This approach directly resolves the security vulnerabilities of over-privileged default accounts by implementing least-privilege custom identities, while following established enterprise lifecycle practices to prevent catastrophic configuration loss caused by premature service account deletion.
Attach the Google APIs Service Agent to the Compute Engine instances, and delete decommissioned service accounts immediately after revoking their access scopes.
Modify the Compute Engine Service Agent roles to grant custom permissions, and use IAM deny policies to disable decommissioned service accounts indefinitely without deleting them.
Recreate the default Compute Engine service account with minimal IAM roles, and immediately delete decommissioned service accounts because recreating an account with the same email restores its prior IAM bindings.