Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A financial enterprise is updating its identity governance and privilege escalation policies across several Google Cloud production projects. The security team wants to eliminate permanent administrative role bindings, establish automated justification and approval workflows for time-bound access elevations integrated with their ITSM platform, and automatically detect when dormant service accounts are granted unauthorized impersonation roles.
Which combination of Google Cloud features should the security engineer implement to satisfy these requirements?
Implement Access Context Manager conditional levels with Chrome Enterprise Premium user-risk policies; configure VPC Service Controls perimeters and rely on custom Cloud Functions parsing Cloud Logging export sinks.
Enforce OS Login with 2-step verification across all Compute Engine instances; configure Organization Policies with iam.disableServiceAccountKeyCreation and automated Cloud KMS key rotation.
Configure Policy Troubleshooter automated remediation rules; implement Principal Access Boundary policies to restrict dormant service account delegation chains across projects.
Configure Privileged Access Manager (PAM) entitlements requiring justification and automated service account approvers for ITSM integration; monitor Security Command Center Event Threat Detection for dormant service account impersonation findings and apply IAM Recommender recommendations.
Implement Access Context Manager conditional levels with Chrome Enterprise Premium user-risk policies; configure VPC Service Controls perimeters and rely on custom Cloud Functions parsing Cloud Logging export sinks.
Enforce OS Login with 2-step verification across all Compute Engine instances; configure Organization Policies with iam.disableServiceAccountKeyCreation and automated Cloud KMS key rotation.
Configure Policy Troubleshooter automated remediation rules; implement Principal Access Boundary policies to restrict dormant service account delegation chains across projects.
Configure Privileged Access Manager (PAM) entitlements requiring justification and automated service account approvers for ITSM integration; monitor Security Command Center Event Threat Detection for dormant service account impersonation findings and apply IAM Recommender recommendations.
Privileged Access Manager (PAM) is a Google Cloud-native service that manages just-in-time, temporary privilege elevation for principals based on defined entitlements. Security Command Center Event Threat Detection is a built-in threat intelligence engine that continuously analyzes Cloud Audit Logs to uncover anomalous IAM behaviors and policy violations, such as privileges granted on dormant accounts. IAM Recommender analyzes historical access patterns to detect excessive permissions and recommend least-privilege role adjustments.
Privilege Escalation: Impersonation Role Granted for Dormant Service Account when a principal gains impersonation rights over a service account inactive for more than 180 days.This approach leverages native Google Cloud governance and security mechanisms to establish automated privilege escalation control, enforce least privilege, and detect dormant account risks without introducing custom management infrastructure.