Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A security engineer is designing a credential delegation workflow for an automated pipeline that impersonates a privilege-bearing service account using the IAM Service Account Credentials API (iamcredentials.googleapis.com). The pipeline must generate specific short-lived credentials to fulfill three separate operational requirements:
Which combination of IAM Service Account Credentials API methods and short-lived credential types should the engineer use?
generateAccessToken with the Cloud Run URL supplied as the OAuth scope.signJwt to construct a signed storage claim for the HTTP PUT operation.generateIdToken to authenticate calls to Google Cloud REST APIs.generateIdToken to produce an OpenID Connect (OIDC) ID token with the target audience claim.signBlob to sign the payload required for a Cloud Storage signed URL.generateAccessToken to produce an OAuth 2.0 access token with appropriate OAuth scopes.signJwt to produce a custom JWT containing user identity claims for Cloud Run.generateAccessToken with Credential Access Boundaries to create the upload URL.signBlob to sign individual REST API requests for infrastructure management.generateIdToken with the cloud-platform OAuth scope.generateAccessToken to sign the Cloud Storage HTTP PUT query parameters.generateIdToken with the audience set to https://cloudresourcemanager.googleapis.com.generateAccessToken with the Cloud Run URL supplied as the OAuth scope.signJwt to construct a signed storage claim for the HTTP PUT operation.generateIdToken to authenticate calls to Google Cloud REST APIs.generateIdToken to produce an OpenID Connect (OIDC) ID token with the target audience claim.signBlob to sign the payload required for a Cloud Storage signed URL.generateAccessToken to produce an OAuth 2.0 access token with appropriate OAuth scopes.Each short-lived credential format generated by the IAM Service Account Credentials API (iamcredentials.googleapis.com) is tailored for specific authentication, authorization, and cryptographic use cases across Google Cloud.
generateIdToken method generates a signed JSON Web Token (JWT) containing an aud (audience) claim matching the target service URL.signBlob method uses the service account's Google-managed private key held in escrow to sign the arbitrary payload without exporting or exposing the private key.Authorization: Bearer header. Calling generateAccessToken creates a temporary, short-lived OAuth 2.0 access token restricted by requested OAuth scopes.aud claim, preventing replay attacks against other services.signBlob delegates time-bounded bucket access to external parties without granting them IAM roles or service account credentials.signJwt to produce a custom JWT containing user identity claims for Cloud Run.generateAccessToken with Credential Access Boundaries to create the upload URL.signBlob to sign individual REST API requests for infrastructure management.generateIdToken with the cloud-platform OAuth scope.generateAccessToken to sign the Cloud Storage HTTP PUT query parameters.generateIdToken with the audience set to https://cloudresourcemanager.googleapis.com.