Google Professional Cloud Security Engineer Exam - Topic 4 Question 52 Discussion
You plan to deploy your cloud infrastructure using a CI/CD cluster hosted on Compute Engine. You want to minimize the risk of its credentials being stolen by a third party. What should you do?
D) Create a custom service account for the cluster Enable the constraints/iam.allowServiceAccountCredentialLifetimeExtension organization policy at the project level.
A) Create a dedicated Cloud Identity user account for the cluster. Use a strong self-hosted vault solution to store the user's temporary credentials.
B) Create a dedicated Cloud Identity user account for the cluster. Enable the constraints/iam.disableServiceAccountCreation organization policy at the project level.
C) Create a custom service account for the cluster Enable the constraints/iam.disableServiceAccountKeyCreation organization policy at the project level.
Galen
10 months agoKristel
10 months agoMarguerita
10 months agoPhil
11 months agoEttie
11 months agoBlondell
11 months agoElza
11 months agoLindy
11 months agoOctavio
11 months agoElza
11 months agoAn
11 months agoChandra
11 months agoQuentin
11 months agoBonita
11 months ago