🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 26 minutes remaining!

GCP Professional Cloud Security Engineer Practice Question

Your security team reviews a new GKE cluster that will run several workloads. All Pods currently use the cluster's default Compute Engine service account, which still holds the Project Editor role. Front-end Pods only need to write logs to Cloud Logging and read one Secret Manager secret. Background worker Pods need to read and write objects in a single Cloud Storage bucket and publish to one Pub/Sub topic. To meet Google-recommended least-privilege practices for service accounts, what should you recommend?

  • Keep the default Compute Engine service account but replace the Editor role with Logging Admin, Secret Manager Secret Accessor, Storage Object Admin, and Pub/Sub Publisher roles at the project level.

  • Delete the default Compute Engine service account and run the node pool with no service account; instead, add the required legacy OAuth scopes to the nodes so Pods can call Google APIs directly.

  • Enable Workload Identity Federation and let all Pods impersonate the Cloud Build service account, which already has wide permissions; leave the default Compute Engine service account unchanged.

  • Create two new Google service accounts-one for the front-end Pods and one for the worker Pods-grant each only the needed roles, map the corresponding KSAs to these GSAs with Workload Identity, and disable the default Compute Engine service account.

GCP Professional Cloud Security Engineer
Configuring Access
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot