Google Professional Cloud DevOps Engineer exam dumps

Google Professional Cloud DevOps Engineer practice question 185 of 268

Professional Cloud DevOps Engineer. Associate level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud DevOps Engineer Question 185

Select 3Google Cloud Platform

Your team is building a CI/CD pipeline on Google Cloud and needs to ensure that a specific service account used by your build process has the minimum required permissions to deploy resources to Google Kubernetes Engine (GKE). Which actions should you take to securely configure the service account?

  1. A

    Grant the 'Kubernetes Engine Developer' role to the service account.

  2. B

    Enable the 'IAM Service Account Token Creator' role on the service account.

  3. C

    Limit the service account's usage to the specific GKE cluster by using a custom role.

  4. D

    Add the service account to the 'Owner' role for the entire project.

  5. E

    Restrict the service account's key usage by rotating or disabling unused keys.

Show answer and explanation

Correct answers: A, C, E

Explanation

When creating and managing service accounts, it's important to follow security best practices, such as granting the minimum required permissions (principle of least privilege) and limiting potential misuse. In this scenario, the 'Kubernetes Engine Developer' role provides the required permissions for deploying to GKE, and a custom role can restrict the service account's scope to a specific cluster. Additionally, securing service account keys by rotating or disabling unused keys prevents unauthorized access. Avoid granting excessive permissions, such as the 'Owner' role, to maintain a secure environment.

  • A. Correct.

    Granting the 'Kubernetes Engine Developer' role provides the minimum required permissions for deploying resources to GKE, aligning with the principle of least privilege.

  • B. Incorrect.

    The 'IAM Service Account Token Creator' role is not necessary for this scenario because it is used for impersonating service accounts, which is unrelated to deploying resources to GKE.

  • C. Correct.

    Using a custom role to limit usage to a specific GKE cluster adds an additional layer of security, ensuring the service account cannot affect other GKE resources.

  • D. Incorrect.

    Granting the 'Owner' role to the service account violates the principle of least privilege and gives it excessive permissions across the project.

  • E. Correct.

    Rotating or disabling unused service account keys reduces the risk of unauthorized access and follows security best practices.

Timed practice exam

Take a Google Professional Cloud DevOps Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam