Google Professional Cloud Security Engineer Exam - Topic 4 Question 52 Discussion
You plan to deploy your cloud infrastructure using a CI/CD cluster hosted on Compute Engine. You want to minimize the risk of its credentials being stolen by a third party. What should you do?
D) Create a custom service account for the cluster Enable the constraints/iam.allowServiceAccountCredentialLifetimeExtension organization policy at the project level.
A) Create a dedicated Cloud Identity user account for the cluster. Use a strong self-hosted vault solution to store the user's temporary credentials.
B) Create a dedicated Cloud Identity user account for the cluster. Enable the constraints/iam.disableServiceAccountCreation organization policy at the project level.
C) Create a custom service account for the cluster Enable the constraints/iam.disableServiceAccountKeyCreation organization policy at the project level.
Galen
9 months agoKristel
9 months agoMarguerita
9 months agoPhil
9 months agoEttie
9 months agoBlondell
9 months agoElza
9 months agoLindy
9 months agoOctavio
10 months agoElza
10 months agoAn
10 months agoChandra
10 months agoQuentin
10 months agoBonita
10 months ago