Google Professional Cloud DevOps Engineer exam dumps

Google Professional Cloud DevOps Engineer practice question 12 of 268

Professional Cloud DevOps Engineer. Associate level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud DevOps Engineer Question 12

Select 2Google Cloud Platform

You are a DevOps Engineer managing a critical production application on Google Cloud. The application runs on Compute Engine instances and requires access to Cloud Storage and Cloud Pub/Sub. To follow best practices for security and least privilege, you need to create and configure service accounts. What steps should you take to ensure the service accounts are configured appropriately for this use case?

  1. A

    Create a dedicated service account for the application and grant it only the roles necessary to access Cloud Storage and Cloud Pub/Sub.

  2. B

    Use the default Compute Engine service account and grant it the roles necessary to access Cloud Storage and Cloud Pub/Sub.

  3. C

    Grant the Owner role to the service account to ensure it has all necessary permissions.

  4. D

    Use Workload Identity Federation to associate the service account with the application for secure, short-lived credential access.

  5. E

    Regularly audit the service account's permissions and remove any unnecessary roles.

Show answer and explanation

Correct answers: A, E

Explanation

To securely manage service accounts for a production application, it is critical to follow the principle of least privilege by creating a dedicated service account with only the necessary roles. Additionally, regularly auditing permissions ensures the service account remains secure and compliant with best practices. Using the default Compute Engine service account or granting overly broad roles like Owner can expose the application to unnecessary risks.

  • A. Correct.

    This is correct. Creating a dedicated service account with only the necessary roles ensures the principle of least privilege and avoids over-permissioning.

  • B. Incorrect.

    This is not recommended because the default Compute Engine service account has broad permissions, which violates the principle of least privilege.

  • C. Incorrect.

    Granting the Owner role gives excessive permissions and violates the principle of least privilege, making it a poor security practice.

  • D. Incorrect.

    Workload Identity Federation is primarily used for integrating identities from external identity providers, not for internal applications running on Google Cloud resources.

  • E. Correct.

    This is correct. Regularly auditing and refining permissions ensures the service account does not retain unnecessary access over time, improving security.

Timed practice exam

Take a Google Professional Cloud DevOps Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam