Cloud Digital Leader Trust and security with Google Cloud Practice Question
Which TWO of the following are best practices for securing a Google Cloud environment? (Choose two.)
⚠ Common exam trap
Google Cloud often tests the misconception that service account key rotation is a best practice, but the trap here is that the real best practice is to avoid using service account keys altogether in favor of workload identity federation or short-lived credentials.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Grant minimal permissions to users and services using IAM roles.
Option B is correct because the principle of least privilege is a core Google Cloud security best practice: IAM roles should be scoped so users and service accounts receive only the permissions required for their tasks, reducing the blast radius of compromised credentials. Option E is correct because enabling VPC Flow Logs on all subnets provides network telemetry for auditing, anomaly detection, and incident response, which is a recommended detective control in Google Cloud. Option A is not a best practice because reusing one SSH key across all Compute Engine instances means a single key compromise grants access to every VM; keys should be unique per user/instance and managed via OS Login or metadata. Option C is not recommended because exporting long-lived service account keys for on-premises use creates high-risk credentials that can be leaked; workload identity federation or short-lived tokens should be used instead. Option D is not among the best practices here because Google recommends avoiding service account keys altogether and, when unavoidable, rotating them regularly rather than treating a fixed monthly rotation as the primary control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the same SSH key for all Compute Engine instances.
Why it's wrong here
Sharing a single SSH key across all Compute Engine instances collapses access management into one point of failure; if the private key is exfiltrated, every instance is compromised. It also prevents per-user accountability, since use of the shared key cannot be traced to an individual person, and forces a blanket rotation for all instances even if only one user leaves. Best practice is to use unique keys per user or integrate with OS Login / Cloud IAP to provide identity-based access.
- ✓
Grant minimal permissions to users and services using IAM roles.
Why this is correct
IAM roles provide granular, auditable control over who can perform specific actions on specific resources, and granting only the minimum permissions needed (least privilege) contains the blast radius of a compromised account or service. Predefined roles like roles/viewer or custom roles with targeted permissions allow you to align access with actual job duties, reducing the chance of accidental or malicious damage. This is a cornerstone of Google Cloud security and is far more effective than managing broad permissions or long-lived credentials.
- ✗
Export service account keys and use them in on-premises applications for authentication.
Why it's wrong here
Exporting service account keys converts a managed cloud identity into a static, long-lived secret that remains valid until manually rotated. Distributing that key to on-premises systems expands the trust boundary far beyond GCP, making it difficult to control access or revoke privileges if the external environment is breached. Google recommends avoiding the creation and export of service account keys entirely, and instead using workload identity federation or short-lived OAuth tokens to authenticate on-premises workloads.
- ✗
Rotate service account keys every month.
Why it's wrong here
Monthly key rotation is not a universal or sufficient security practice; the real risk is the existence of long-lived static keys, regardless of how frequently they are replaced. A rotated key may still have been leaked, and rotation only protects against future misuse—it does not detect or neutralize an active compromise. Modern GCP best practice is to avoid the use of service account keys altogether by leveraging workload identity federation or auto-rotated, short-lived credentials, which eliminate the need for manual rotation schedules.
- ✓
Enable VPC Flow Logs for all subnets.
Why this is correct
VPC Flow Logs capture per-interface metadata about IP traffic within and into your VPC, recording source/destination, protocol, ports, and packet counts. Enabling them for all subnets gives your security team comprehensive visibility for detecting anomalies like port scans, data exfiltration, or lateral movement, and provides an evidence trail for forensic analysis and compliance audits. While there is a cost for log ingestion and storage, the security value of having full network telemetry generally outweighs that overhead.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Compute Comparison: VMs vs Containers vs Serverless
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
Key term
Network telemetry
Network telemetry is the automated process of collecting, transmitting, and analyzing data from network devices to monitor performance, detect issues, and improve security in real time.
About these practice questions
This GCDL question is part of Courseiva's 848-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.