Courseiva

Cloud Digital Leader Trust and security with Google Cloud Practice Question

Which TWO of the following are best practices for securing a Google Cloud environment? (Choose two.)

⚠ Common exam trap

Google Cloud often tests the misconception that service account key rotation is a best practice, but the trap here is that the real best practice is to avoid using service account keys altogether in favor of workload identity federation or short-lived credentials.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Grant minimal permissions to users and services using IAM roles.

Option B is correct because the principle of least privilege is a core Google Cloud security best practice: IAM roles should be scoped so users and service accounts receive only the permissions required for their tasks, reducing the blast radius of compromised credentials. Option E is correct because enabling VPC Flow Logs on all subnets provides network telemetry for auditing, anomaly detection, and incident response, which is a recommended detective control in Google Cloud. Option A is not a best practice because reusing one SSH key across all Compute Engine instances means a single key compromise grants access to every VM; keys should be unique per user/instance and managed via OS Login or metadata. Option C is not recommended because exporting long-lived service account keys for on-premises use creates high-risk credentials that can be leaked; workload identity federation or short-lived tokens should be used instead. Option D is not among the best practices here because Google recommends avoiding service account keys altogether and, when unavoidable, rotating them regularly rather than treating a fixed monthly rotation as the primary control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use the same SSH key for all Compute Engine instances.

    Why it's wrong here

    Sharing a single SSH key across all Compute Engine instances collapses access management into one point of failure; if the private key is exfiltrated, every instance is compromised. It also prevents per-user accountability, since use of the shared key cannot be traced to an individual person, and forces a blanket rotation for all instances even if only one user leaves. Best practice is to use unique keys per user or integrate with OS Login / Cloud IAP to provide identity-based access.

  • ✓

    Grant minimal permissions to users and services using IAM roles.

    Why this is correct

    IAM roles provide granular, auditable control over who can perform specific actions on specific resources, and granting only the minimum permissions needed (least privilege) contains the blast radius of a compromised account or service. Predefined roles like roles/viewer or custom roles with targeted permissions allow you to align access with actual job duties, reducing the chance of accidental or malicious damage. This is a cornerstone of Google Cloud security and is far more effective than managing broad permissions or long-lived credentials.

  • ✗

    Export service account keys and use them in on-premises applications for authentication.

    Why it's wrong here

    Exporting service account keys converts a managed cloud identity into a static, long-lived secret that remains valid until manually rotated. Distributing that key to on-premises systems expands the trust boundary far beyond GCP, making it difficult to control access or revoke privileges if the external environment is breached. Google recommends avoiding the creation and export of service account keys entirely, and instead using workload identity federation or short-lived OAuth tokens to authenticate on-premises workloads.

  • ✗

    Rotate service account keys every month.

    Why it's wrong here

    Monthly key rotation is not a universal or sufficient security practice; the real risk is the existence of long-lived static keys, regardless of how frequently they are replaced. A rotated key may still have been leaked, and rotation only protects against future misuse—it does not detect or neutralize an active compromise. Modern GCP best practice is to avoid the use of service account keys altogether by leveraging workload identity federation or auto-rotated, short-lived credentials, which eliminate the need for manual rotation schedules.

  • ✓

    Enable VPC Flow Logs for all subnets.

    Why this is correct

    VPC Flow Logs capture per-interface metadata about IP traffic within and into your VPC, recording source/destination, protocol, ports, and packet counts. Enabling them for all subnets gives your security team comprehensive visibility for detecting anomalies like port scans, data exfiltration, or lateral movement, and provides an evidence trail for forensic analysis and compliance audits. While there is a cost for log ingestion and storage, the security value of having full network telemetry generally outweighs that overhead.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This GCDL question is part of Courseiva's 848-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.