Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 112 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 112

Select 2Google Cloud Platform

Your organization is using Google Cloud to host a multi-tier application. The front-end tier and back-end tier run in separate projects, and your team uses Service Accounts to manage communication between the tiers. To ensure secure and principle-of-least-privilege access, how should you configure the authorization controls for the back-end Service Account used by the front-end application?

  1. A

    Grant the Service Account Viewer role at the organization level.

  2. B

    Assign the Service Account User role for the front-end project to the back-end Service Account.

  3. C

    Grant the Service Account a custom role with specific permissions to access only the back-end resources it needs.

  4. D

    Use IAM Conditions to restrict the Service Account's access to specific resources and contexts.

  5. E

    Grant the Service Account Editor role at the project level for both the front-end and back-end projects.

Show answer and explanation

Correct answers: C, D

Explanation

To ensure secure and fine-grained access control, the Service Account should be granted a custom role (Option 3) with only the specific permissions needed for its tasks. Additionally, using IAM Conditions (Option 4) can restrict access further, providing contextual control over how and when the Service Account can access the back-end resources. These practices align with the principle of least privilege and minimize potential security risks.

  • A. Incorrect.

    Granting the Viewer role at the organization level gives excessive access and violates the principle of least privilege. This option is not recommended in this scenario.

  • B. Incorrect.

    The Service Account User role allows a user or entity to act as the Service Account but does not provide the necessary resource-specific permissions for the back-end tier. This is not a correct configuration to manage access.

  • C. Correct.

    A custom role with specific permissions ensures that the Service Account has only the necessary access to back-end resources. This aligns with the principle of least privilege.

  • D. Correct.

    IAM Conditions can add contextual restrictions, such as limiting access to specific resource types or actions, further enhancing security. This is a best practice for managing authorization controls.

  • E. Incorrect.

    Granting the Editor role at the project level is overly permissive and violates the principle of least privilege. This option should be avoided.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam