StudyToCert

All certifications / Associate Cloud Engineer / Lessons

Google Cloud Associate Cloud Engineer Associate Cloud Engineer · Domain 4: Configuring access and security

Service account impersonation, short-lived credentials and avoiding service account keys

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

A service account key is a long-lived private key file (JSON) that anyone can use to authenticate as the service account, from anywhere, until the key is deleted or disabled. Keys are one of the most common causes of cloud breaches because they get copied into source code, laptops, CI systems and chat messages. Google's guidance is to avoid creating keys whenever another option exists, and many organizations block key creation with the iam.disableServiceAccountKeyCreation organization policy.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 4 more sections, 4 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study Associate Cloud Engineer for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the Associate Cloud Engineer study plan