Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise executes automated CI/CD deployment pipelines on an external computing platform. The security architecture team requires that external workloads access Google Cloud resources to deploy infrastructure across multiple projects without using downloadable service account keys. Furthermore, the team mandates that service account impersonation must be strictly restricted to jobs originating from specific repositories and branch references asserted in the external identity provider's token.
Which strategy should the security engineer implement to establish this federation trust relationship?
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.