Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 41 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 41

Select 3Google Cloud Platform

Your organization has multiple Google Cloud projects, and you want to centralize the management of service accounts. The security team has requested that you follow best practices to minimize the risk of privilege escalation and unauthorized access. Which of the following actions should you take to manage service accounts securely?

  1. A

    Grant the Service Account User role only to trusted users or groups.

  2. B

    Use the default Compute Engine service account for all workloads across projects.

  3. C

    Enable the 'Disable service account key creation' organization policy.

  4. D

    Rotate service account keys regularly if using key-based authentication.

  5. E

    Grant the Service Account Admin role to all team members to allow flexibility in creating and managing accounts.

Show answer and explanation

Correct answers: A, C, D

Explanation

Managing service accounts securely requires following the principle of least privilege, avoiding the use of default service accounts, and ensuring that long-lived keys are minimized or rotated. Granting roles such as Service Account User or Admin should be done cautiously and only to trusted entities. By enforcing these practices, you reduce the attack surface and improve the overall security posture of your Google Cloud environment.

  • A. Correct.

    Granting the Service Account User role only to trusted users or groups is a best practice to limit who can impersonate service accounts and prevent unauthorized access.

  • B. Incorrect.

    Using the default Compute Engine service account across projects is not recommended because it can lead to over-permissioned accounts and violates the principle of least privilege.

  • C. Correct.

    Enabling the 'Disable service account key creation' organization policy prevents the creation of long-lived keys, which reduces the risk of key compromise.

  • D. Correct.

    Rotating service account keys regularly is a security best practice to minimize the risk of key exposure and unauthorized access if a key is compromised.

  • E. Incorrect.

    Granting the Service Account Admin role to all team members is not advised, as it could lead to over-provisioning of permissions and an increased risk of privilege escalation.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam