Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
A security engineer is configuring access for a new data pipeline in Google Cloud. The deployment involves two projects:
Workloads running on Compute Engine in Project A must use a user-managed service account named data-processor@project-a.iam.gserviceaccount.com to read BigQuery data in Project B. A DevOps engineer needs permission to deploy and configure Compute Engine instances in Project A and attach data-processor@project-a.iam.gserviceaccount.com to those instances. The DevOps engineer must not be permitted to attach or impersonate any other service account in Project A, nor access BigQuery data directly with their personal identity.
Which combination of IAM role bindings meets these requirements while enforcing least privilege?
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.