You are designing a new Google Cloud organization for a client. Your client is concerned with the risks associated with long-lived credentials created in Google Cloud. You need to design a solution to completely eliminate the risks associated with the use of JSON service account keys while minimizing operational overhead. What should you do?
The correct answer is B, Apply the constraints/iam.disableServiceAccountKeyCreation constraint to the organization.
The other options are incorrect because they do not completely eliminate the risks associated with the use of JSON service account keys. Option A is incorrect because it only restricts the IAM permissions to create, list, get, delete, or sign service account keys, but it does not prevent existing keys from being used or leaked. Option C is incorrect because it only disables the upload of user-managed service account keys, but it does not prevent the creation or download of such keys. Option D is incorrect because it only limits the IAM role that can create and manage service account keys, but it does not prevent the keys from being distributed or exposed to unauthorized entities.
Miesha
9 months agoErasmo
10 months agoRocco
10 months agoFelicitas
10 months agoLuis
10 months agoCecily
10 months agoJesse
11 months agoJesus
11 months agoWillard
11 months agoIsaiah
11 months agoNoble
11 months agoSarah
11 months agoCristy
11 months agoCallie
11 months agoVilma
11 months agoSharen
11 months agoColette
11 months agoAnjelica
11 months agoCatarina
2 years agoTuyet
2 years agoRaelene
2 years agoCammy
2 years agoNilsa
2 years agoJacki
2 years agoAgustin
2 years agoTish
2 years ago