Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise runs long-running batch analytics jobs on Amazon Web Services (AWS) EC2 instances that process and load data directly into Google Cloud BigQuery and Cloud Storage. The security team identified that developers are currently using downloaded, long-lived service account JSON keys on AWS, violating corporate security policies.
The security engineer must replace these static keys with Workload Identity Federation using AWS instance profiles. The batch pipeline runs for 4 consecutive hours, requiring a single short-lived impersonated service account token with a 4-hour (14,400-second) lifetime.
Which set of actions should the security engineer take to implement this architecture?
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.