Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 44 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 44

Select 3Google Cloud Platform

Your organization has several Google Cloud projects, and you notice that some Compute Engine instances are using the default Compute Engine service account with overly permissive roles, such as 'Editor.' As a Professional Cloud Security Engineer, what steps should you take to secure the usage of service accounts across projects?

  1. A

    Restrict the permissions of the default Compute Engine service account by following the principle of least privilege.

  2. B

    Disable the default Compute Engine service account entirely to prevent its use.

  3. C

    Use custom service accounts with narrowly scoped IAM roles for Compute Engine instances wherever possible.

  4. D

    Apply organization policies to prevent the use of default service accounts in your projects.

  5. E

    Grant the 'Owner' role to the default Compute Engine service account to ensure it can access all resources when needed.

Show answer and explanation

Correct answers: A, C, D

Explanation

To secure and protect service accounts, especially default service accounts, it is important to follow the principle of least privilege by restricting permissions and using custom service accounts with scoped roles when possible. Additionally, organization policies can enforce these practices consistently across projects. Disabling the default service account or granting it excessive permissions are not recommended approaches, as they either undermine functionality or increase security risks.

  • A. Correct.

    This is correct because restricting permissions for the default Compute Engine service account minimizes risk by following the principle of least privilege, ensuring it only has the access it truly requires.

  • B. Incorrect.

    This is incorrect because disabling the default Compute Engine service account is not a recommended approach. There may be valid use cases for it, and its functionality should be managed rather than completely disabled.

  • C. Correct.

    This is correct because creating and using custom service accounts with narrowly scoped roles is a best practice for securing workloads and adhering to the principle of least privilege.

  • D. Correct.

    This is correct because applying organization policies to restrict the use of default service accounts enforces secure practices across all projects in the organization.

  • E. Incorrect.

    This is incorrect because granting the 'Owner' role to the default Compute Engine service account provides excessive permissions, violating the principle of least privilege and increasing the risk of privilege escalation.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam