Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 48 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 48

Select 2Google Cloud Platform

You are responsible for securing your organization's Google Cloud environment. A developer has created a custom application that runs on Compute Engine instances and uses a default Compute Engine service account to access other Google Cloud services. As a security best practice, what steps should you take to secure and protect the service account used by this application?

  1. A

    Restrict the permissions of the default Compute Engine service account to only those required by the application.

  2. B

    Delete the default Compute Engine service account and replace it with a new service account specifically created for this application.

  3. C

    Enable the 'Disable service account key creation' policy for the default Compute Engine service account.

  4. D

    Rotate the credentials of the default Compute Engine service account regularly to minimize security risks.

  5. E

    Set up workload identity federation for the default Compute Engine service account to limit the use of long-lived credentials.

Show answer and explanation

Correct answers: A, C

Explanation

To secure and protect service accounts, it is critical to adhere to the principle of least privilege by restricting permissions to only those required for the application. Additionally, disabling service account key creation reduces the risk of unauthorized access through key compromise. These are key security best practices for managing and securing service accounts, including default service accounts.

  • A. Correct.

    Restricting permissions of the default Compute Engine service account follows the principle of least privilege and is a recommended security best practice.

  • B. Incorrect.

    Deleting the default Compute Engine service account is not recommended as it is required for Compute Engine functionality unless you explicitly replace it with another service account. However, simply replacing it does not inherently improve security unless coupled with other best practices.

  • C. Correct.

    Enabling the 'Disable service account key creation' policy prevents the creation of long-lived external keys, reducing the risk of key compromise.

  • D. Incorrect.

    Rotating credentials is not applicable to default service accounts as they use automatically managed credentials. This option is not relevant in this scenario.

  • E. Incorrect.

    Workload identity federation is typically used for accessing Google Cloud resources from on-premises or external environments, not for securing default service accounts on Compute Engine.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam