mediumMultiple Choice
Google ACE Practice Question: A security review identifies that service account…
A security review identifies that service account JSON key files are stored on multiple developer laptops, posing a data exfiltration risk. What is the recommended remediation?
⚠ Common exam trap
Google Cloud often tests the misconception that moving a secret to a more secure storage (like Secret Manager or encryption) is sufficient, when the correct answer requires eliminating the static credential entirely through impersonation or workload identity federation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Remove the key files and use service account impersonation or Workload Identity for workloads that need GCP access
Storing service account JSON key files on developer laptops creates a persistent credential that can be exfiltrated. The recommended remediation is to remove these static keys entirely and instead use service account impersonation (via the `iamcredentials.googleapis.com` API) or Workload Identity (for GKE or GCE workloads) to obtain short-lived access tokens. This eliminates the long-lived secret and follows Google's principle of using federated identity rather than distributing static keys.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Rotate the key files every 90 days and redistribute them securely
Why it's wrong here
Rotating key files every 90 days reduces the exposure window if a key leaks but leaves the fundamental vulnerability in place: a private key file still lives on developer laptops, CI/CD systems, or application servers. Each rotation triggers a new secure distribution process, which itself introduces opportunties for interception or accidental disclosure. Google recommends against long-lived service account keys altogether; using metadata server tokens or service account impersonation provides short-lived credentials that rotate automatically and require no key distribution.
- ✗
Encrypt the JSON key files using Cloud KMS before distributing
Why it's wrong here
Encrypting JSON key files with Cloud KMS before distribution merely adds a layer of obfuscation while assuming the key must exist; the application still has to call Cloud KMS to decrypt the key at runtime, which requires a separate credential and IAM permission to access the KMS key. Once decrypted, the key material is written to local memory or disk, so a host compromise yields both the encrypted key and the ability to decrypt it. This is a defense-in-depth measure that reduces risk slightly, but it does not eliminate the danger inherent in using service account keys.
- ✓
Remove the key files and use service account impersonation or Workload Identity for workloads that need GCP access
Why this is correct
The correct approach is to eliminate service account key files entirely. For workloads on GCE or GKE, attach a service account to the resource and let the metadata server provide OAuth2 tokens automatically; GKE can use Workload Identity to bind a Kubernetes service account to a Google service account. For external or on-premises workloads, configure Workload Identity Federation to exchange tokens from an external identity provider for short-lived GCP access tokens. This removes the risk of private key material being stolen and relies on IAM to define exactly which identities get which permissions.
- ✗
Store the key files in Secret Manager and retrieve them at application startup
Why it's wrong here
Storing the JSON key in Secret Manager and loading it at application startup improves key management but still requires the raw key material to exist in the application's runtime environment. Every time the service starts, it must retrieve or decrypt the key and hold it in memory, so if the process or container is compromised the key can be exfiltrated. Secret Manager is appropriate for storing secrets, but it doesn't address the core problem: a long-lived service account key should not exist at all when GCP-native short-lived credentials are available.
Go deeper
Related to this question
Learn chapter
BigQuery Authorized Views for Access Control
Key term
GKE
GKE is Google's managed Kubernetes service that automates deploying, scaling, and managing containerized applications in the cloud.
Key term
Service
A service is a software component or system that performs a specific function and is available to be used by other programs or users over a network.
About these practice questions
One of 775 original ACE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.