Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
A security engineer needs to configure access for an engineer (developer@example.com) who must generate short-lived OAuth 2.0 access tokens to impersonate a specific deployment service account (deploy-prod@example-proj.iam.gserviceaccount.com) from their local environment. The project contains multiple sensitive service accounts used by critical infrastructure.
To uphold the principle of least privilege and prevent unintentional privilege escalation, how should the security engineer grant the necessary access?
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.