Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
A multinational enterprise is hardening its Google Cloud environment against identity compromise and unauthorized privilege escalation. The security operations team identified that attackers might attempt to chain service account impersonations or exploit dormant and default service accounts to perform unauthorized administrative actions. The team needs to establish a comprehensive strategy to meet the following requirements:
Which combination of controls and tools should the security engineer implement?
This solution combines Security Command Center (SCC) Event Threat Detection (ETD), Google Cloud Organization Policy Service, and IAM Recommender to establish end-to-end detection, prevention, and remediation for service account security.
Privilege Escalation: Anomalous Multistep Service Account Delegation for Admin Activity and Privilege Escalation: Impersonation Role Granted for Dormant Service Account. It analyzes the delegation chain, identifying the initial caller and intermediary impersonated principals.iam.disableServiceAccountKeyCreation at the organization root blocks users and automation pipelines from generating user-managed private key files (.json), forcing workloads to use secure, short-lived tokens and workload identity federation.This approach directly aligns with Google Cloud security best practices by pairing preventive guardrails (Organization Policies) with continuous runtime threat detection (SCC Event Threat Detection) and intelligent rightsizing (IAM Recommender).
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.