🔥 40% Off Crucial Exams Memberships — Deal ends today!

3 hours, 1 minute remaining!

GCP Professional Cloud Security Engineer Practice Question

A multinational enterprise maintains an on-premises middleware service that must authenticate to Google Cloud Storage by using a JSON key for a Google Cloud service account. Compliance now mandates quarterly key rotation with zero downtime for the application. Which practice best satisfies Google-recommended guidance for rotating this unavoidable user-managed key while minimizing service disruption?

  • Create a second key for the service account, update the application to use the new key, verify access, and then delete the original key-ensuring no more than two active keys exist at any time.

  • Delete the current key, immediately create a replacement with the same name, and restart the application to force it to pick up the new credential.

  • Periodically re-encrypt the existing key with a new Cloud KMS key version to satisfy rotation requirements without generating additional service account keys.

  • Extend the key's expiration date to 90 days and enable OS-level credential caching so the application keeps working during the renewal window.

GCP Professional Cloud Security Engineer
Configuring Access
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot