Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 57 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 57

Select 3Google Cloud Platform

Your organization has deployed a critical application on Google Cloud. The application requires a service account to interact with other Google Cloud services. You need to ensure that the service account is created securely, authorized only with the necessary IAM roles, and disabled when not in use. Which of the following actions should you take to meet these requirements?

  1. A

    Create the service account with a descriptive name and assign it the 'Editor' role at the project level for broad access.

  2. B

    Grant the service account only the IAM roles that provide the minimum permissions required for the application to function.

  3. C

    Use the Principle of Least Privilege when authorizing the service account to access Google Cloud resources.

  4. D

    Disable the service account when it is no longer needed or is temporarily not in use.

  5. E

    Enable the 'Service Account User' role on the service account for all users to allow them to impersonate it.

Show answer and explanation

Correct answers: B, C, D

Explanation

To securely create and manage a service account, it is essential to follow security best practices such as using the Principle of Least Privilege, assigning only necessary IAM roles, and disabling the account when it is not in use. These measures help ensure that the service account is used securely and does not pose unnecessary risks to the organization's resources.

  • A. Incorrect.

    Assigning the 'Editor' role at the project level provides broad access and violates the Principle of Least Privilege. This is not a secure practice.

  • B. Correct.

    Granting the service account only the required IAM roles aligns with security best practices and minimizes the risk of abuse or accidental access.

  • C. Correct.

    The Principle of Least Privilege ensures that the service account has only the permissions required to perform its tasks, improving the overall security posture.

  • D. Correct.

    Disabling the service account when it is not needed reduces the risk of its misuse or compromise.

  • E. Incorrect.

    Granting the 'Service Account User' role to all users is not a secure practice and can lead to unauthorized access to resources. Only trusted individuals should be allowed to impersonate the service account.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam