🔥 40% Off Crucial Exams Memberships — Deal ends today!

2 hours, 29 minutes remaining!

GCP Professional Cloud Security Engineer Practice Question

Your organization keeps its production resources in project "prod-123" and runs all build pipelines in project "cicd-456". Security policy bans any long-lived service-account keys. A new pipeline executed by the Cloud Build default service account ([email protected]) must deploy updated Cloud Run services in prod-123. Engineers plan to invoke gcloud with the flag --impersonate-service-account=prod-deployer@prod-123.iam.gserviceaccount.com. Which set of IAM configuration changes will enable the deployment while honoring the security policy and the principle of least privilege?

  • In cicd-456, grant the Cloud Build service account roles/iam.serviceAccountUser on prod-deployer, and directly grant Cloud Build Cloud Run Admin in prod-123; prod-deployer needs no additional roles.

  • In prod-123, grant the Cloud Build service account the role roles/iam.serviceAccountTokenCreator on the prod-deployer service account, and grant the prod-deployer service account only the required Cloud Run deployment roles within prod-123.

  • Create a JSON key for the prod-deployer service account, store it in Secret Manager, and allow the Cloud Build service account to access the secret; ensure prod-deployer has Cloud Run Admin in prod-123.

  • Place both projects inside a VPC Service Controls perimeter and grant the Cloud Build service account roles/iam.serviceAccountAdmin on prod-deployer; no further role bindings are required.

GCP Professional Cloud Security Engineer
Configuring Access
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot