GCP Professional Cloud Security Engineer Practice Question
Your organization runs hundreds of microservices across three GKE projects. The platform team is enabling mutual TLS and will use cert-manager to obtain workload certificates from a centrally managed CAS deployment. Requirements: 1) keep a single root of trust, 2) cert-manager service accounts must request and renew certificates yet never disable, delete, or modify CAs, 3) apply least-privilege IAM. Which IAM role should you grant each cert-manager service account on the relevant CA Pool (or its subordinate CAs) to satisfy these constraints?
Grant roles/viewer and let cert-manager impersonate a Cloud KMS key to sign CSRs programmatically.
Grant roles/privateca.admin to the cert-manager service accounts at the project level that hosts the CAS deployment.
Grant roles/privateca.caManager to each cert-manager service account on every Certificate Authority in the pool.
Grant roles/privateca.certificateRequester to each cert-manager service account on the relevant CA Pool or subordinate CAs.
The predefined role roles/privateca.certificateRequester contains permissions such as privateca.certificates.create and privateca.certificates.get to issue and renew certificates, while offering only read-level access to Certificate Authorities. It lacks any permissions to update, disable, or delete CAs or CA pools, so it enforces least privilege and meets requirement 2. Roles like privateca.caManager or privateca.admin would allow CA modification, and the Viewer role does not permit certificate issuance.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is CAS in the context of GCP certificate management?
Open an interactive chat with Bash
What does the role roles/privateca.certificateRequester specifically allow?
Open an interactive chat with Bash
Why is mutual TLS important for microservices security?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .