Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise organization is deploying Workload Identity Federation across multiple external continuous integration (CI/CD) platforms to access Google Cloud resources securely. The security team needs to establish a comprehensive security and auditing baseline for the federation lifecycle.
The implementation must satisfy two primary requirements:
Which configuration strategy should the security engineer implement?
This strategy establishes an end-to-end security architecture for Workload Identity Federation (WIF) by combining deep audit logging with strict administrative boundaries and immutable claim mappings.
sts.googleapis.com). Enabling Data Access audit logs ensures that every token exchange event—along with its mapped external attributes—is permanently captured.GenerateAccessToken are recorded in Identity and Access Management (IAM) API Data Access logs, providing an unbroken audit trail back to the originating external identity even when downstream resource APIs do not natively populate serviceAccountDelegationInfo.roles/iam.workloadIdentityPoolAdmin role, preventing unauthorized actors from inheriting iam.googleapis.com/workloadIdentityPoolProviders.update permissions from parent folders.Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.