Courseiva

CHFI Application, Email and Cloud Forensics Practice Question

A GCP audit log shows a project owner granted 'iam.serviceAccountUser' role to a service account from a different project. Which TWO potential security implications should the investigator prioritize?

⚠ Common exam trap

The distinction between 'iam.serviceAccountUser' (which allows using the service account on resources) and 'iam.serviceAccountTokenCreator' (which allows impersonation and token generation) is often tested, leading candidates to mistakenly think the role enables user impersonation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The service account can be used to escalate privileges by attaching it to resources

Option A is correct because the iam.serviceAccountUser role grants the ability to attach a service account to a resource (for example, deploying a Compute Engine instance or Cloud Function that runs as that service account), which can let a principal act with the service account's permissions and escalate privileges. Option D is correct because granting this role to a service account from a different project creates a cross-project trust path, enabling lateral movement from the attacker's project into the target project's resources. Option B is wrong because granting iam.serviceAccountUser does not disable or modify audit logging. Option C is wrong because key rotation is not triggered by this role grant and is unrelated to it. Option E is wrong because iam.serviceAccountUser does not grant user impersonation; that requires roles/iam.serviceAccountTokenCreator or the iam.serviceAccounts.getAccessToken permission.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The service account can be used to escalate privileges by attaching it to resources

    Why this is correct

    The iam.serviceAccountUser role permits a principal to attach that service account to Compute Engine instances or other resources, inheriting its permissions. Granting it cross-project lets the grantee impersonate the service account and thereby escalate beyond their own project's rights.

  • ✗

    The audit logging is now disabled for that service account

    Why it's wrong here

    Granting iam.serviceAccountUser does not alter audit logging configuration; Cloud Audit Logs remain enabled independently of IAM bindings. It is tempting because service account misuse often accompanies attempts to cover tracks, but disabling logging requires explicitly modifying audit config or excluding the service account, not this role grant.

  • ✗

    The service account's keys are automatically rotated

    Why it's wrong here

    Automatic key rotation is a security control, not an implication of granting iam.serviceAccountUser across projects. That role lets a principal impersonate the service account, so the investigator should prioritise privilege escalation and lateral movement; rotation would only be relevant when assessing key management.

  • ✓

    Cross-project access may allow lateral movement

    Why this is correct

    Because the service account belongs to a different project, the grant creates a trust path between projects. An attacker compromising the grantee can pivot through the service account into the other project's resources, enabling lateral movement across project boundaries that IAM normally isolates.

  • ✗

    The service account can now impersonate any user in the project

    Why it's wrong here

    The iam.serviceAccountUser role permits attaching a service account to resources, not impersonating arbitrary users; impersonation requires the Service Account Token Creator role. It tempts because the role name suggests broad user-level access, and would be correct if the granted role were roles/iam.serviceAccountTokenCreator.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.