Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
A multinational enterprise is designing a just-in-time (JIT) privileged access architecture in Google Cloud for their production storage environment. The security team has defined the following operational and compliance requirements:
sre-team@example.com group) and an automated deployment pipeline identity (deploy-runner@proj.iam.gserviceaccount.com) must be able to temporarily elevate to roles/storage.admin.itsm-validator@proj.iam.gserviceaccount.com) to eliminate manual bottlenecks.Which Privileged Access Manager (PAM) entitlement configuration meets these requirements?
Privileged Access Manager (PAM) is a Google Cloud security service designed to manage, automate, and audit just-in-time (JIT) privilege elevation. PAM uses entitlements as policy definitions that establish which principals can request elevated roles, what roles can be obtained, the maximum grant lifespan, mandatory justifications, and approval workflows.
sre-team@example.com) and non-human identities (service accounts like deploy-runner@proj.iam.gserviceaccount.com). Service accounts can self-elevate for automated deployment tasks rather than holding permanent high-privilege bindings.gcloud pam grants approve or REST endpoint) using the itsm-validator service account credentials, removing manual operator delays.APPROVAL_AWAITED or ACTIVE state.roles/privilegedaccessmanager.admin). They only interact with their assigned requester and approver bindings.This architecture directly satisfies all least-privilege, multi-identity, automation, and governance requirements using native Google Cloud PAM functionality without custom infrastructure or unnecessary privilege delegation.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.