Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise hosts a customer-facing application on Google Compute Engine virtual machines. During a penetration test, security analysts discover a Server-Side Request Forgery (SSRF) vulnerability that allows external actors to inject custom HTTP request headers and query the instance metadata server (http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/default/token). The red team demonstrated that by stealing the default Compute Engine service account token, they could leverage overly broad IAM permissions to modify the instance startup-script metadata on other production virtual machines, achieving remote code execution and privilege escalation.
Which strategy should the security engineer implement to remediate this attack vector and detect subsequent exploitation attempts?
Rely entirely on the Metadata-Flavor: Google header check on the metadata server and deploy Cloud IDS to block Layer 7 HTTP requests targeted at 169.254.169.254.
Assign dedicated, least-privilege service accounts to VMs lacking metadata modification roles, and monitor Security Command Center Event Threat Detection for Compute Engine Admin Added Startup Script findings.
Implement Cloud Storage Bucket Lock on instance logging buckets and enforce Binary Authorization on the Compute Engine virtual machine instances.
Configure a VPC egress firewall rule to deny all internal network traffic to the link-local metadata IP address 169.254.169.254.
Rely entirely on the Metadata-Flavor: Google header check on the metadata server and deploy Cloud IDS to block Layer 7 HTTP requests targeted at 169.254.169.254.
Assign dedicated, least-privilege service accounts to VMs lacking metadata modification roles, and monitor Security Command Center Event Threat Detection for Compute Engine Admin Added Startup Script findings.
This strategy combines least-privilege IAM identity governance with native threat detection via Security Command Center Event Threat Detection (ETD) to eliminate lateral privilege escalation and monitor unauthorized instance metadata modifications.
roles/editor) role by default. Replacing it with a custom service account containing only minimal data plane permissions ensures that any stolen access token cannot be used to modify other cloud resources or escalate privileges.compute.instances.setMetadata permission ensures compromised tokens cannot alter VM configuration attributes like startup-script or ssh-keys.Compute Engine Admin Added Startup Script when metadata changes occur on established instances.While technical safeguards such as the Metadata-Flavor: Google header mitigate basic SSRF, an attacker with full header injection can still query metadata endpoints. Restricting the underlying IAM role and auditing metadata updates via ETD provides robust, defense-in-depth protection against privilege escalation.
Implement Cloud Storage Bucket Lock on instance logging buckets and enforce Binary Authorization on the Compute Engine virtual machine instances.
Configure a VPC egress firewall rule to deny all internal network traffic to the link-local metadata IP address 169.254.169.254.