🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 27 minutes remaining!

GCP Professional Cloud Architect Practice Question

Your security team wants to grant an external automation system running in GitHub Actions the ability to deploy container images to a production Cloud Run service that resides in project "prod-app," but nothing else in the project. The automation already authenticates with GitHub's OIDC token. You create a workload identity pool and provider in the prod-app project. Which approach best satisfies least privilege while eliminating long-lived service account keys?

  • Bind the Cloud Run Admin predefined role to the GitHub workload identity principal at the project level.

  • Export a JSON key for a dedicated service account with the Cloud Run Admin role and store it as a GitHub Actions secret.

  • Allow the GitHub workload identity principal to impersonate a dedicated service account that has the Cloud Run Developer role on the specific Cloud Run service.

  • Create a custom role containing only run.services.invoke and bind it to the GitHub principal at the organization level.

GCP Professional Cloud Architect
Designing for security and compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot