Google Professional Cloud Security Engineer Exam - Topic 4 Question 52 Discussion
You plan to deploy your cloud infrastructure using a CI/CD cluster hosted on Compute Engine. You want to minimize the risk of its credentials being stolen by a third party. What should you do?
D) Create a custom service account for the cluster Enable the constraints/iam.allowServiceAccountCredentialLifetimeExtension organization policy at the project level.
A) Create a dedicated Cloud Identity user account for the cluster. Use a strong self-hosted vault solution to store the user's temporary credentials.
B) Create a dedicated Cloud Identity user account for the cluster. Enable the constraints/iam.disableServiceAccountCreation organization policy at the project level.
C) Create a custom service account for the cluster Enable the constraints/iam.disableServiceAccountKeyCreation organization policy at the project level.
Galen
7 months agoKristel
7 months agoMarguerita
7 months agoPhil
8 months agoEttie
8 months agoBlondell
8 months agoElza
8 months agoLindy
8 months agoOctavio
8 months agoElza
8 months agoAn
8 months agoChandra
8 months agoQuentin
8 months agoBonita
8 months ago