Q: 12
A company’s application is deployed with a user-managed Service Account key. You want to use
Google- recommended practices to rotate the key.
What should you do?
Options
Discussion
D tbh, since storing the old key as backup sounds safer in case the new one fails. Similar question came up in practice and it seemed logical, but now not fully sure if Google likes that. Nice clear scenario.
Feels like C, saw this style Q in some exam reports. Google wants you to delete old keys after migration for least privilege, not keep backups. If I'm off here let me know.
I don’t think D is correct. C matches Google’s recommended approach because keeping the old key (D) increases risk if it’s compromised.
Probably C, since keeping the old key (like D says) is actually risky from a security perspective. Google wants you to delete unused keys after switch. A and B aren’t real commands for this scenario.
Be respectful. No spam.