Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 157 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 157

Select 2Google Cloud Platform

Your organization has a policy that requires users to have elevated permissions only when performing certain administrative tasks within Google Cloud. You are tasked with configuring Privileged Access Manager (PAM) to enforce this policy. Which configurations should you implement to meet this requirement?

  1. A

    Create Access Approval policies that require users to submit a request for elevated permissions.

  2. B

    Define Just-In-Time (JIT) access policies to grant temporary permissions for administrative tasks.

  3. C

    Enable Organization Policy constraints to restrict all elevated permissions by default.

  4. D

    Set up predefined IAM roles with elevated permissions and assign them permanently to users.

  5. E

    Configure session duration limits for elevated roles through Privileged Access Manager.

Show answer and explanation

Correct answers: B, E

Explanation

To meet the organization's policy of granting elevated permissions only when necessary, Privileged Access Manager's Just-In-Time (JIT) access policies and session duration limits should be used. JIT ensures permissions are granted temporarily for specific tasks, and session duration limits enforce the time-bound nature of these permissions, reducing the risk of misuse.

  • A. Incorrect.

    Access Approval policies are related to obtaining approval for actions on sensitive data or resources, not specifically for managing privileged access requests.

  • B. Correct.

    Just-In-Time (JIT) access policies are a core feature of Privileged Access Manager that allow temporary elevation of privileges only when necessary, aligning with the organization's policy.

  • C. Incorrect.

    While Organization Policy constraints can restrict permissions, they do not provide the flexibility required for temporary role elevation as provided by Privileged Access Manager.

  • D. Incorrect.

    Assigning elevated IAM roles permanently to users contradicts the principle of least privilege and does not align with the use case of temporary access.

  • E. Correct.

    Privileged Access Manager allows you to configure session duration limits for elevated roles, ensuring that elevated permissions are granted only for the time necessary to complete specific tasks.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam