Professional Cloud DevOps Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Your organization uses an external CI/CD pipeline running in an external cloud provider to deploy application infrastructure. The pipeline needs to decrypt sensitive deployment configuration files using a Cloud KMS key before initiating rollout.
To meet strict security compliance, your implementation must satisfy the following requirements:
Which configuration should you implement?
This architecture establishes a secure, keyless authentication bridge between external CI/CD pipeline runners and Google Cloud resources by combining Workload Identity Federation (WIF), fine-grained Cloud Key Management Service (Cloud KMS) access control, and comprehensive Cloud Audit Logging.
roles/cloudkms.cryptoKeyDecrypter strictly at the individual CryptoKey level (rather than across the entire KeyRing or project) ensures the service account can only decrypt payloads without having permissions to encrypt, destroy, or manage key configurations.Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.