Courseiva
mediumMultiple Choice

Google ACE Practice Question: A security review identifies that service account…

A security review identifies that service account JSON key files are stored on multiple developer laptops, posing a data exfiltration risk. What is the recommended remediation?

⚠ Common exam trap

Google Cloud often tests the misconception that moving a secret to a more secure storage (like Secret Manager or encryption) is sufficient, when the correct answer requires eliminating the static credential entirely through impersonation or workload identity federation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Remove the key files and use service account impersonation or Workload Identity for workloads that need GCP access

Storing service account JSON key files on developer laptops creates a persistent credential that can be exfiltrated. The recommended remediation is to remove these static keys entirely and instead use service account impersonation (via the `iamcredentials.googleapis.com` API) or Workload Identity (for GKE or GCE workloads) to obtain short-lived access tokens. This eliminates the long-lived secret and follows Google's principle of using federated identity rather than distributing static keys.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Rotate the key files every 90 days and redistribute them securely

    Why it's wrong here

    Rotating key files every 90 days reduces the exposure window if a key leaks but leaves the fundamental vulnerability in place: a private key file still lives on developer laptops, CI/CD systems, or application servers. Each rotation triggers a new secure distribution process, which itself introduces opportunties for interception or accidental disclosure. Google recommends against long-lived service account keys altogether; using metadata server tokens or service account impersonation provides short-lived credentials that rotate automatically and require no key distribution.

  • ✗

    Encrypt the JSON key files using Cloud KMS before distributing

    Why it's wrong here

    Encrypting JSON key files with Cloud KMS before distribution merely adds a layer of obfuscation while assuming the key must exist; the application still has to call Cloud KMS to decrypt the key at runtime, which requires a separate credential and IAM permission to access the KMS key. Once decrypted, the key material is written to local memory or disk, so a host compromise yields both the encrypted key and the ability to decrypt it. This is a defense-in-depth measure that reduces risk slightly, but it does not eliminate the danger inherent in using service account keys.

  • ✓

    Remove the key files and use service account impersonation or Workload Identity for workloads that need GCP access

    Why this is correct

    The correct approach is to eliminate service account key files entirely. For workloads on GCE or GKE, attach a service account to the resource and let the metadata server provide OAuth2 tokens automatically; GKE can use Workload Identity to bind a Kubernetes service account to a Google service account. For external or on-premises workloads, configure Workload Identity Federation to exchange tokens from an external identity provider for short-lived GCP access tokens. This removes the risk of private key material being stolen and relies on IAM to define exactly which identities get which permissions.

  • ✗

    Store the key files in Secret Manager and retrieve them at application startup

    Why it's wrong here

    Storing the JSON key in Secret Manager and loading it at application startup improves key management but still requires the raw key material to exist in the application's runtime environment. Every time the service starts, it must retrieve or decrypt the key and hold it in memory, so if the process or container is compromised the key can be exfiltrated. Secret Manager is appropriate for storing secrets, but it doesn't address the core problem: a long-lived service account key should not exist at all when GCP-native short-lived credentials are available.

About these practice questions

One of 775 original ACE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.