Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise organization wants to implement a just-in-time (JIT) privileged access strategy for its site reliability engineering (SRE) team on a production folder in Google Cloud.
The security solution must satisfy the following operational and compliance requirements:
Which solution should the organization implement?
Grant permanent conditional IAM role bindings directly in the folder allow policy using CEL expressions with request.time < timestamp(...) that are updated by manual administrative intervention during incidents.
Assign the elevated IAM roles to a Google Group at the folder level, and deploy a custom Cloud Function that adds and removes users from the Google Group upon ticket approval.
Create Privileged Access Manager (PAM) entitlements at the folder level configured with the SREs as eligible requesters, designated lead engineers as approvers, mandatory justification, the required elevated IAM roles, and a maximum grant duration.
Enable Access Approval on the folder and configure lead engineers as approval contacts to validate individual administrative API requests submitted by SREs.
Grant permanent conditional IAM role bindings directly in the folder allow policy using CEL expressions with request.time < timestamp(...) that are updated by manual administrative intervention during incidents.
Assign the elevated IAM roles to a Google Group at the folder level, and deploy a custom Cloud Function that adds and removes users from the Google Group upon ticket approval.
Create Privileged Access Manager (PAM) entitlements at the folder level configured with the SREs as eligible requesters, designated lead engineers as approvers, mandatory justification, the required elevated IAM roles, and a maximum grant duration.
Privileged Access Manager (PAM) is a Google Cloud-native service designed to manage, automate, and audit just-in-time (JIT) temporary privilege elevation for users and service accounts across organizations, folders, and projects.
Native PAM entitlements provide an automated, policy-driven, and fully audited framework for temporary privilege escalation, eliminating custom script maintenance, API rate-limit concerns, and standing privilege risks.
Enable Access Approval on the folder and configure lead engineers as approval contacts to validate individual administrative API requests submitted by SREs.