Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 77 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 77

Select 3Google Cloud Platform

Your organization uses an external identity provider (IdP) to authenticate workloads running in AWS and Azure. You need to allow these workloads to securely access resources in Google Cloud without creating and managing long-lived service account keys. How should you configure Workload Identity Federation to achieve this?

  1. A

    Create a Workload Identity Pool and define a provider for each external IdP.

  2. B

    Grant the IAM role 'Workload Identity User' to the external identities at the project level.

  3. C

    Configure AWS or Azure to use short-lived tokens that can be exchanged for Google Cloud credentials.

  4. D

    Create a service account in Google Cloud and bind it to the Workload Identity Pool.

  5. E

    Enable private Google access on the VPCs hosting the workloads in AWS and Azure.

Show answer and explanation

Correct answers: A, C, D

Explanation

Workload Identity Federation allows you to securely authenticate workloads running in external environments like AWS or Azure without managing long-lived service account keys. To set up Workload Identity Federation, you need to create a Workload Identity Pool, define providers for each external IdP, configure the external environment to generate short-lived tokens, and bind a Google Cloud service account to the Workload Identity Pool. This setup ensures secure, federated access to Google Cloud resources.

  • A. Correct.

    Correct. Creating a Workload Identity Pool and defining providers for each external IdP is the first step in enabling Workload Identity Federation.

  • B. Incorrect.

    Incorrect. The 'Workload Identity User' role is granted to the Google Cloud service account, not the external identities.

  • C. Correct.

    Correct. Configuring AWS or Azure to use short-lived tokens allows you to securely exchange these for Google Cloud credentials without needing long-lived keys.

  • D. Correct.

    Correct. A Google Cloud service account is required and must be bound to the Workload Identity Pool to allow external workloads to act as the service account.

  • E. Incorrect.

    Incorrect. Enabling private Google access is not required for Workload Identity Federation. It is typically used for private connectivity to Google APIs from within a VPC.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam