GCP Professional Cloud Security Engineer Practice Question
Your security team is mapping identities to workloads in a large Google Cloud environment. Which of the following requirements must be implemented with a Google Cloud service account rather than a human user or group identity?
A batch job running on a managed instance group writes nightly inventory data from Cloud SQL to BigQuery.
Data analysts run BigQuery queries from their laptops each morning using the bq command-line tool.
External auditors need temporary read-only access to the Cloud Console for a two-week engagement.
On-call engineers occasionally SSH into production Linux VMs via IAP for troubleshooting.
On-call engineers accessing production VMs through IAP-based SSH sessions
Data analysts using the bq CLI from their personal workstations
The batch job on the managed instance group that exports data from Cloud SQL to BigQuery
External auditors requesting two weeks of read-only Cloud Console access
A service account represents a non-human identity intended for code running on a workload such as a VM or container. The batch job on the managed instance group is an automated process with no interactive user, so it should authenticate to BigQuery with a dedicated service account that has only the required permissions. The analysts, auditors, and on-call engineers are people; they should use individual or group-based user identities protected by MFA and time-bound IAM roles, not service accounts.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why does the batch job require a service account instead of a human identity?
Open an interactive chat with Bash
What best practices should be followed for service account permissions?
Open an interactive chat with Bash
When should human identities be used instead of service accounts?
Open an interactive chat with Bash
What is a service account in Google Cloud?
Open an interactive chat with Bash
Why can't human users or groups use service accounts?
Open an interactive chat with Bash
What are the security best practices for managing service accounts?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Configuring Access
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .