🔥 40% Off Crucial Exams Memberships — Deal ends today!

46 minutes, 37 seconds remaining!

GCP Professional Cloud Security Engineer Practice Question

A company's on-premises Jenkins controller runs in a data center that already issues OpenID Connect (OIDC) ID tokens for each build agent. The build pipeline must push container images to Artifact Registry and apply manifests to several Google Kubernetes Engine clusters that reside in different projects. Security policy forbids long-lived service account keys and mandates least-privilege access. Which approach best satisfies the requirements while minimizing ongoing operational effort?

  • Create a Workload Identity Pool and OIDC provider, allow the Jenkins-issued tokens to impersonate a dedicated Google Cloud service account, and grant that account only the roles needed for Artifact Registry and GKE deployments.

  • Grant the Compute Engine default service account the Editor role in each project and reference that account in the Jenkins pipeline using service account impersonation.

  • Configure Jenkins jobs to launch Cloud Shell sessions with gcloud auth login and use the authenticated user's credentials to perform deployments.

  • Create a new service account key in JSON format, store it as a secret in Jenkins, and rotate the key every 90 days.

GCP Professional Cloud Security Engineer
Configuring Access
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot