Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 54 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 54

Select 3Google Cloud Platform

You are a Security Engineer managing the Google Cloud environment for your company. You are tasked with creating a new service account for a custom application that will access resources in your project. After creating the service account, you need to ensure that it can only access a specific Cloud Storage bucket. Which of the following steps should you take to meet the requirements?

  1. A

    Create the service account and assign it the Storage Admin role at the project level.

  2. B

    Create the service account and assign it the Storage Object Viewer role at the bucket level.

  3. C

    Disable the service account to prevent unauthorized access.

  4. D

    Add the service account to the IAM policy for the specific Cloud Storage bucket, granting it the necessary permissions.

  5. E

    Verify that the service account key is securely stored, or avoid creating keys if not needed.

Show answer and explanation

Correct answers: B, D, E

Explanation

To meet the requirements, you need to create a service account with permissions limited to the specific Cloud Storage bucket. Assigning the Storage Object Viewer role at the bucket level ensures the service account has the necessary read-only access to the bucket. Adding the service account to the bucket’s IAM policy ensures permissions are scoped correctly. Additionally, securely managing service account keys or avoiding key creation altogether helps maintain security best practices.

  • A. Incorrect.

    Assigning the Storage Admin role at the project level grants excessive permissions that are not restricted to the specific bucket, thereby violating the principle of least privilege.

  • B. Correct.

    Assigning the Storage Object Viewer role at the bucket level grants the service account read-only access to the specific bucket, which aligns with the requirement of limiting access to that bucket only.

  • C. Incorrect.

    Disabling the service account would prevent it from functioning, which is not aligned with the task of enabling access for the custom application.

  • D. Correct.

    Adding the service account to the IAM policy for the specific Cloud Storage bucket ensures that permissions are scoped correctly, adhering to the principle of least privilege.

  • E. Correct.

    Ensuring that the service account key is securely stored or avoiding key creation (when possible) is a best practice to mitigate potential security risks.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam