Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
A security engineer is designing an authentication architecture for enterprise workloads running in Amazon Web Services (AWS) and Microsoft Azure that need to access Cloud Storage buckets in Google Cloud.
To comply with organizational security policies, the architecture must satisfy the following requirements:
Which solution should the engineer implement to meet these requirements?
Workload Identity Federation is a Google Cloud IAM capability that enables workloads running outside Google Cloud (such as in AWS, Microsoft Azure, GitHub Actions, or on-premises environments) to impersonate service accounts or directly access Google Cloud resources by exchanging external identity tokens for short-lived, ephemeral Google Cloud access tokens.
.json service account keys stored on external infrastructure. Trust is established cryptographically via identity federation.google.subject, google.groups, or attribute.custom_name), allowing access to be bound directly to specific principalSet:// strings in IAM allow policies.principal:// and principalSet:// without requiring service account impersonation.This approach aligns with Google Cloud security best practices by eliminating static secrets while preserving fine-grained authorization across hybrid and multi-cloud architectures.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.