GCP Professional Cloud Security Engineer Practice Question

Your security team discovered that a third-party component in one of your Compute Engine VMs can be tricked into making arbitrary HTTP requests (a potential SSRF vector). The application still needs to retrieve instance identity tokens from the metadata server for workload identity federation. Which control most effectively reduces the risk of an attacker exfiltrating the token without breaking the application's legitimate calls?

  • Delete the VM's default service account so that no OAuth tokens are ever issued by the metadata server.

  • Enable the project metadata key "block-project-ssh-keys" to prevent automatic SSH key injection into the VM.

  • Create an egress VPC firewall rule denying all traffic to 169.254.169.254 from the VM subnet.

  • Set the project metadata key "disable-legacy-endpoints" to "true" so that only the v1 metadata path requiring the Metadata-Flavor header remains reachable.

GCP Professional Cloud Security Engineer
Ensuring data protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot