Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise uses an external continuous deployment (CD) pipeline to deploy build artifacts into a specific Google Cloud Storage bucket (bucket-prod-artifacts). The designated service account (deployer-sa@project-id.iam.gserviceaccount.com) has the Storage Object Admin role at the project level.
To adhere to least-privilege security principles, the security engineer must implement a solution that fulfills the following requirements:
deployer-sa.bucket-prod-artifacts, preventing access to any other buckets.Which strategy should the security engineer implement?
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.