Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 43 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 43

Select 4Google Cloud Platform

Your organization uses multiple service accounts in Google Cloud for application workloads. A recent audit revealed that some default service accounts have excessive permissions. To comply with the principle of least privilege, which steps should you take to secure and protect these service accounts?

  1. A

    Restrict the default service account's roles to only those necessary for its workload.

  2. B

    Disable unused default service accounts to prevent unauthorized access.

  3. C

    Grant the Owner role to all default service accounts to ensure functionality.

  4. D

    Enable the Workload Identity Federation feature to eliminate the use of long-lived service account keys.

  5. E

    Avoid using default service accounts altogether and create custom service accounts for each workload.

Show answer and explanation

Correct answers: A, B, D, E

Explanation

To secure and protect service accounts, it's crucial to follow best practices such as restricting permissions, disabling unused accounts, and leveraging features like Workload Identity Federation. Avoid using default service accounts when possible, as creating custom service accounts allows for better control and adherence to the principle of least privilege. Granting excessive permissions, such as the Owner role, contradicts security best practices and should be avoided.

  • A. Correct.

    Restricting the default service account's roles minimizes the risk of privilege escalation and ensures adherence to the principle of least privilege.

  • B. Correct.

    Disabling unused default service accounts prevents them from being exploited by attackers or used inappropriately.

  • C. Incorrect.

    Granting the Owner role to service accounts violates the principle of least privilege and increases the risk of misuse; this is not a recommended practice.

  • D. Correct.

    Enabling Workload Identity Federation removes the need for long-lived service account keys, reducing the risk of key compromise.

  • E. Correct.

    Avoiding default service accounts and creating custom service accounts ensures you can better tailor permissions to each specific workload.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam