Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 83 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 83

Single answerGoogle Cloud Platform

Your organization uses Google Cloud and follows the principle of least privilege. You need to grant a developer the ability to impersonate a service account used by a critical application to perform specific tasks. However, you want to ensure the developer can only impersonate this service account temporarily and for specific actions. What is the best way to achieve this?

  1. A

    Grant the developer the 'Service Account Token Creator' role on the service account and define a detailed IAM policy specifying the allowed tasks.

  2. B

    Grant the developer the 'Editor' role on the project containing the service account.

  3. C

    Grant the developer the 'Service Account User' role on the service account and enforce restrictions using a custom IAM condition.

  4. D

    Grant the developer the 'Owner' role on the service account for the duration of the required tasks and revoke it afterward.

Show answer and explanation

Correct answer: C

Explanation

The best solution is to grant the 'Service Account User' role to the developer on the specific service account, as it allows impersonation. To further restrict access, you can attach IAM conditions to the role, such as time-based constraints or limitations on specific actions. This approach aligns with the principle of least privilege by ensuring the developer has only the necessary permissions for the required tasks.

  • A. Incorrect.

    This option is incorrect because the 'Service Account Token Creator' role only allows the developer to generate tokens for authentication but does not inherently restrict what tasks can be performed with the impersonated service account.

  • B. Incorrect.

    This option is incorrect because the 'Editor' role grants excessive permissions at the project level, which violates the principle of least privilege.

  • C. Correct.

    This option is correct because the 'Service Account User' role allows the developer to impersonate the service account, and IAM conditions can be used to enforce time-based or action-specific restrictions, ensuring compliance with the principle of least privilege.

  • D. Incorrect.

    This option is incorrect because the 'Owner' role provides unrestricted permissions to the service account, which is unnecessary and risks violating the principle of least privilege.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam