Professional Cloud DevOps Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
Your organization uses an external CI/CD pipeline running in an external cloud provider to deploy application infrastructure. The pipeline needs to decrypt sensitive deployment configuration files using a Cloud KMS key before initiating rollout.
To meet strict security compliance, your implementation must satisfy the following requirements:
Which configuration should you implement?
Create a service account with roles/cloudkms.admin on the target CryptoKey, assign the pipeline runner roles/iam.workloadIdentityPoolAdmin on the project, and export audit logs to BigQuery.
Configure a Workload Identity Pool mapping external usernames, grant the federated principal roles/cloudkms.cryptoKeyEncrypterDecrypter on the parent KeyRing, and enable default Cloud Logging for Cloud KMS.
Generate a downloadable JSON service account key for a deployment service account, assign it roles/cloudkms.cryptoKeyDecrypter at the project level, and enable Security Command Center audit alerting.
Configure a Workload Identity Pool mapping stable external claims, grant the federated identity roles/iam.workloadIdentityUser on a dedicated service account, grant that service account roles/cloudkms.cryptoKeyDecrypter specifically on the target CryptoKey, and enable Data Access audit logs for the Security Token Service and IAM APIs.
Create a service account with roles/cloudkms.admin on the target CryptoKey, assign the pipeline runner roles/iam.workloadIdentityPoolAdmin on the project, and export audit logs to BigQuery.
Configure a Workload Identity Pool mapping external usernames, grant the federated principal roles/cloudkms.cryptoKeyEncrypterDecrypter on the parent KeyRing, and enable default Cloud Logging for Cloud KMS.
Generate a downloadable JSON service account key for a deployment service account, assign it roles/cloudkms.cryptoKeyDecrypter at the project level, and enable Security Command Center audit alerting.
Configure a Workload Identity Pool mapping stable external claims, grant the federated identity roles/iam.workloadIdentityUser on a dedicated service account, grant that service account roles/cloudkms.cryptoKeyDecrypter specifically on the target CryptoKey, and enable Data Access audit logs for the Security Token Service and IAM APIs.
This architecture establishes a secure, keyless authentication bridge between external CI/CD pipeline runners and Google Cloud resources by combining Workload Identity Federation (WIF), fine-grained Cloud Key Management Service (Cloud KMS) access control, and comprehensive Cloud Audit Logging.
roles/cloudkms.cryptoKeyDecrypter strictly at the individual CryptoKey level (rather than across the entire KeyRing or project) ensures the service account can only decrypt payloads without having permissions to encrypt, destroy, or manage key configurations.