Professional Cloud DevOps Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Your team is building automated infrastructure management scripts in Python and Go using the official Google Cloud Client Libraries. To comply with organizational security baselines, developers are strictly prohibited from downloading, exporting, or storing long-lived service account private keys (.json key files) on their local workstations.
Developers have already been granted the Service Account Token Creator (roles/iam.serviceAccountTokenCreator) role on the workload service account sa-orchestrator@company-project.iam.gserviceaccount.com.
How should developers configure their local development environments so that the client library scripts authenticate as the service account via Application Default Credentials (ADC) without using exported key files?
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.