🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 51 minutes remaining!

GCP Professional Cloud Security Engineer Practice Question

Your security team wants to eliminate the long-lived Google Cloud service account keys currently stored as Kubernetes secrets in an AWS EKS cluster. The applications running in that cluster must still upload objects to a Cloud Storage bucket in your Google Cloud project. You need a solution that follows Google's recommended practices, keeps credentials short-lived, and minimizes operational overhead. What should you do?

  • Generate a new user-managed service account key, encrypt it with AWS KMS, store it in AWS Secrets Manager, and decrypt it at container start-up.

  • Make the Cloud Storage bucket public and require the application to use signed URLs produced by a helper service in Google Cloud for uploads.

  • Enable GKE Workload Identity in the Google Cloud project and label the EKS pods with the target Google service account to transparently obtain tokens.

  • Create a Workload Identity Pool with an AWS provider, map the EKS cluster's IAM role to a Google Cloud service account with the required Storage roles, and let workloads obtain short-lived tokens through Application Default Credentials.

GCP Professional Cloud Security Engineer
Configuring Access
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot