Professional Cloud Security EngineerConfiguring access within a cloud solution environmentMedium
A security team needs to ensure that all service account keys created within a specific Google Cloud project are rotated every 90 days. They want an automated way to identify service accounts with keys older than 90 days and potentially trigger a rotation process. Which Google Cloud service can help identify these non-compliant keys?
- ASecurity Command Center
- BCloud Monitoring
- CCloud Asset Inventory
- DCloud Audit Logs
Show answer & explanationAnswer & explanation
Correct answer: C. Cloud Asset Inventory
Cloud Asset Inventory provides a detailed history and current state of all Google Cloud assets, including service account keys. It allows querying assets based on creation time and other metadata, making it suitable for identifying keys older than a specific duration for rotation purposes.
Why the other options are wrong
- A. Security Command Center identifies vulnerabilities and threats but doesn't directly provide an inventory query capability for asset age unless integrated with Asset Inventory.
- B. Cloud Monitoring collects metrics and logs for performance and health, not a detailed inventory of asset properties like key age.
- D. Cloud Audit Logs record events but do not provide a real-time inventory or state of assets for querying based on age.
Cloud Asset Inventory (IAM Auditing)
A Google Cloud service that provides a unified, searchable view of all Google Cloud assets across projects and organizations, including their metadata and history.
- Enables auditing, compliance, and security posture management.
- Can query assets by type, properties, and creation time.
- Useful for identifying long-lived resources or non-compliant configurations.
Memory trick: Asset Inventory Identifies All Items.