Google Professional Cloud Security Engineer Exam - Topic 4 Question 5 Discussion
An application running on a Compute Engine instance needs to read data from a Cloud Storage bucket. Your team does not allow Cloud Storage buckets to be globally readable and wants to ensure the principle of least privilege.Which option meets the requirement of your team?
C) Use a service account with read-only access to the Cloud Storage bucket to retrieve the credentials from the instance metadata.
A) Create a Cloud Storage ACL that allows read-only access from the Compute Engine instance's IP address and allows the application to read from the bucket without credentials.
B) Use a service account with read-only access to the Cloud Storage bucket, and store the credentials to the service account in the config of the application on the Compute Engine instance.
D) Encrypt the data in the Cloud Storage bucket using Cloud KMS, and allow the application to decrypt the data with the KMS key.
Lonna
10 months agoNakita
10 months agoTeri
11 months agoAnnelle
11 months agoLorrie
11 months agoKaty
11 months agoBobbye
11 months agoTheresia
11 months agoCarmen
11 months agoTasia
11 months agoStephaine
11 months agoRashad
11 months agoAlease
11 months ago