Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise security engineer is hardening identity governance for a production Google Cloud environment. A security audit reveals that several Compute Engine virtual machines (VMs) are utilizing the Compute Engine default service account (PROJECT_NUMBER-compute@developer.gserviceaccount.com) with the Editor role (roles/editor). Additionally, multiple legacy workloads are being decommissioned, and the operations team plans to immediately delete their associated service accounts.
Which strategy should the security engineer implement to remediate the VM identities and manage the decommissioning lifecycle according to Google Cloud best practices?
User-managed service accounts are custom identities created and managed by administrators within a project to provide workload-specific authentication and authorization. Managing the service account lifecycle by disabling unused accounts before permanently deleting them is a recommended security control that prevents operational disruption while mitigating lateral movement and privilege escalation risks.
roles/editor role.This approach directly resolves the security vulnerabilities of over-privileged default accounts by implementing least-privilege custom identities, while following established enterprise lifecycle practices to prevent catastrophic configuration loss caused by premature service account deletion.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.