Intrigued by the art of cloud architecture? Discover how to design, develop, and manage robust, secure, scalable, and dynamic solutions on Google Cloud as you prepare for the Professional Cloud Architect exam!
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise runs continuous integration and deployment (CI/CD) pipelines on an external cloud platform. Workloads running in these external pipelines need to deploy container images and update infrastructure in Google Cloud.
Company security policies strictly prohibit creating, downloading, and storing long-lived service account key files due to the risk of credential leakage.
What should you do to configure secure, keyless authentication for these external workloads?
Configure Workforce Identity Federation and have pipeline runners authenticate using OAuth 2.0 authorization code flows with user credentials.
Grant the primitive Editor role to the default Compute Engine service account and use Cloud VPN to route external pipeline traffic privately to Google APIs.
Create a dedicated service account with the required IAM roles, generate a downloadable JSON service account key, and store it as an encrypted secret in the external CI/CD pipeline.
Create a Workload Identity Pool and provider, map external token claims to Google Cloud attributes, and grant the Workload Identity User role on a dedicated service account to the federated principal set.
Configure Workforce Identity Federation and have pipeline runners authenticate using OAuth 2.0 authorization code flows with user credentials.
Grant the primitive Editor role to the default Compute Engine service account and use Cloud VPN to route external pipeline traffic privately to Google APIs.
Create a dedicated service account with the required IAM roles, generate a downloadable JSON service account key, and store it as an encrypted secret in the external CI/CD pipeline.
Create a Workload Identity Pool and provider, map external token claims to Google Cloud attributes, and grant the Workload Identity User role on a dedicated service account to the federated principal set.
Workload Identity Federation is Google Cloud's recommended mechanism for granting on-premises and external multi-cloud workloads access to Google Cloud resources without managing long-lived service account keys. It leverages Security Token Service (STS) and IAM to establish a trust relationship with external identity providers (IdPs) supporting OpenID Connect (OIDC) or SAML 2.0.
google.subject, attribute.repository).roles/iam.workloadIdentityUser role on a target service account specifically to the mapped external principal set (principalSet://iam.googleapis.com/...) ensures only authorized external workloads can impersonate the service account.Workload Identity Federation provides a direct, cloud-native standard for keyless authentication across heterogeneous environments, aligning perfectly with security best practices and the principle of least privilege.