Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A multinational enterprise is hardening its Google Cloud environment against identity compromise and unauthorized privilege escalation. The security operations team identified that attackers might attempt to chain service account impersonations or exploit dormant and default service accounts to perform unauthorized administrative actions. The team needs to establish a comprehensive strategy to meet the following requirements:
Which combination of controls and tools should the security engineer implement?
Create Cloud Logging exclusion sinks to filter out IAM Admin Activity logs, grant developers the Service Account Key Admin role with IAM conditions, and deploy Chronicle SOAR playbooks to automatically disable the Google APIs Service Agent.
Deploy Web Security Scanner to crawl IAM API endpoints for delegation vulnerabilities, configure VPC Service Controls perimeters around the IAM API, and use OS Login 2-step verification to block service account key downloads.
Enable Security Command Center Event Threat Detection to analyze Admin Activity audit logs for anomalous delegation and dormant account role assignments, enforce the iam.disableServiceAccountKeyCreation organization policy constraint, and use IAM Recommender alongside finding details to remediate excessive permissions.
Configure VPC Flow Logs with Cloud IDS to inspect IAM token delegation payloads, enforce the constraints/gcp.restrictNonCmekServices organization policy constraint, and write custom Cloud Functions to delete service accounts inactive for 30 days.
Create Cloud Logging exclusion sinks to filter out IAM Admin Activity logs, grant developers the Service Account Key Admin role with IAM conditions, and deploy Chronicle SOAR playbooks to automatically disable the Google APIs Service Agent.
Deploy Web Security Scanner to crawl IAM API endpoints for delegation vulnerabilities, configure VPC Service Controls perimeters around the IAM API, and use OS Login 2-step verification to block service account key downloads.
Enable Security Command Center Event Threat Detection to analyze Admin Activity audit logs for anomalous delegation and dormant account role assignments, enforce the iam.disableServiceAccountKeyCreation organization policy constraint, and use IAM Recommender alongside finding details to remediate excessive permissions.
This solution combines Security Command Center (SCC) Event Threat Detection (ETD), Google Cloud Organization Policy Service, and IAM Recommender to establish end-to-end detection, prevention, and remediation for service account security.
Privilege Escalation: Anomalous Multistep Service Account Delegation for Admin Activity and Privilege Escalation: Impersonation Role Granted for Dormant Service Account. It analyzes the delegation chain, identifying the initial caller and intermediary impersonated principals.iam.disableServiceAccountKeyCreation at the organization root blocks users and automation pipelines from generating user-managed private key files (.json), forcing workloads to use secure, short-lived tokens and workload identity federation.This approach directly aligns with Google Cloud security best practices by pairing preventive guardrails (Organization Policies) with continuous runtime threat detection (SCC Event Threat Detection) and intelligent rightsizing (IAM Recommender).
Configure VPC Flow Logs with Cloud IDS to inspect IAM token delegation payloads, enforce the constraints/gcp.restrictNonCmekServices organization policy constraint, and write custom Cloud Functions to delete service accounts inactive for 30 days.