Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
A security architect is configuring Workload Identity Federation to allow external CI/CD pipelines running on a third-party OpenID Connect (OIDC) identity provider to access Google Cloud resources without using service account keys.
The incoming OIDC ID token contains the following claims:
sub: A unique subject string (under 127 bytes)repository_owner: The organization owning the repository (e.g., example-org)ref: The branch reference (e.g., refs/heads/main)environment: The deployment target environment (e.g., production)The security requirements are:
example-org targeting production can exchange tokens for Google Cloud credentials.Which configuration strategy should the architect implement?
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.