Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 159 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 159

Select 2Google Cloud Platform

Your organization uses Google Cloud to manage critical workloads. Recently, the security team identified that a specific service account used for managing production resources has overly broad permissions. To mitigate risks, the team wants to implement just-in-time access for this service account to ensure that elevated permissions are granted only when absolutely necessary. Which steps should you take to achieve this using Privileged Access Manager?

  1. A

    Configure an access approval policy to require manual approval for elevated permissions.

  2. B

    Create a policy in Privileged Access Manager to define the conditions for just-in-time access.

  3. C

    Enable the Privileged Access Manager API in your Google Cloud project.

  4. D

    Assign the service account to a predefined role with least privilege access.

  5. E

    Set up logging and monitoring in Cloud Audit Logs to track access requests.

Show answer and explanation

Correct answers: B, C

Explanation

To implement just-in-time access using Privileged Access Manager, you need to enable the Privileged Access Manager API and configure policies that define when and how elevated permissions can be granted. This ensures that elevated permissions are only activated when appropriate, reducing security risks. Other options, such as logging, least privilege roles, or access approval policies, are important for security but do not specifically achieve just-in-time access configuration.

  • A. Incorrect.

    Access approval policies are not directly managed by Privileged Access Manager. While access approval can control user access, it does not enforce just-in-time access for service accounts.

  • B. Correct.

    Privileged Access Manager allows you to define just-in-time access policies. Configuring the appropriate conditions is a necessary step to restrict elevated permissions.

  • C. Correct.

    The Privileged Access Manager API must be enabled to configure and enforce just-in-time access policies.

  • D. Incorrect.

    Assigning a predefined role with least privilege is a good security practice but does not implement just-in-time access for elevated permissions.

  • E. Incorrect.

    While logging and monitoring are essential for tracking access requests, they do not directly configure just-in-time access for a service account.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam