🔥 40% Off Crucial Exams Memberships — Deal ends today!

10 minutes, 10 seconds remaining!

GCP Professional Cloud Security Engineer Practice Question

Your organization operates more than 200 Google Cloud projects beneath a single organization node. A new compliance rule states that no one may create new user-managed service account keys, except in one legacy project called "payments-bridge," which must continue to generate key files for an on-premises HSM. The security team wants a solution that (1) blocks key creation everywhere else, (2) supports automatic enforcement for any future projects, and (3) does not rely on ongoing manual administration. What should you do?

  • Create a top-level folder (for example, "restricted-keys"), move all projects except payments-bridge into it, and set constraints/iam.disableServiceAccountKeyCreation to enforced: true on that folder.

  • Remove the Service Account Key Admin role from every project except payments-bridge and ensure future projects do not grant the role.

  • Set the constraints/iam.disableServiceAccountKeyCreation policy to enforced: true at the organization level, then override it with enforced: false in the payments-bridge project.

  • Enable Access Approval organization-wide and deny any approval requests to create new service account keys, allowing approvals only in payments-bridge.

GCP Professional Cloud Security Engineer
Supporting compliance requirements
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot