Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A financial enterprise is hardening its Compute Engine infrastructure in Google Cloud. Security auditors found that developers have excessive privileges that allow them to view and modify sensitive custom instance metadata keys and deploy instances using privileged workload identities.
The security engineer must implement least-privilege access controls with the following requirements:
iam.serviceAccounts.actAs).Which configuration should the security engineer implement?
Grant developers roles/compute.viewer combined with roles/iam.serviceAccountAdmin on the service account, and enforce access tokens with https://www.googleapis.com/auth/devstorage.read_only scope.
Grant developers a role with compute.instances.get on the VM instances, do not grant roles/iam.serviceAccountUser, and set the https://www.googleapis.com/auth/cloud-platform access scope on instances while restricting workload permissions strictly via IAM roles on the attached service account.
Grant developers roles/compute.securityAdmin on the project, assign iam.serviceAccounts.actAs directly to developers on the project root, and disable the metadata server via firewall rules.
Grant developers the predefined roles/compute.instanceAdmin.v1 and roles/iam.serviceAccountUser roles at the project level, and configure VM instances with the restricted https://www.googleapis.com/auth/compute.readonly access scope.
Grant developers roles/compute.viewer combined with roles/iam.serviceAccountAdmin on the service account, and enforce access tokens with https://www.googleapis.com/auth/devstorage.read_only scope.
Grant developers a role with compute.instances.get on the VM instances, do not grant roles/iam.serviceAccountUser, and set the https://www.googleapis.com/auth/cloud-platform access scope on instances while restricting workload permissions strictly via IAM roles on the attached service account.
This solution implements granular Identity and Access Management (IAM) permissions for administrators and developers outside the virtual machine while applying Google Cloud best practices for workload identities and API access scopes on Compute Engine instances.
compute.instances.get permission allows principals to retrieve instance metadata and configuration properties via the Google Cloud CLI, Console, or REST API without granting write permissions.roles/iam.serviceAccountUser role (which grants iam.serviceAccounts.actAs) and omitting compute.instances.setMetadata, developers cannot alter metadata scripts or launch/modify resources acting as the service account.https://www.googleapis.com/auth/cloud-platform access scope on VM instances delegates all authorization enforcement directly to IAM roles assigned to the user-managed service account, avoiding restrictive and inflexible legacy OAuth scope configurations.iam.serviceAccounts.actAs prevents unauthorized users from leveraging service account permissions bound to the VM.cloud-platform scope ensures IAM allow policies remain the single source of truth for application resource access.This approach aligns with Google Cloud architecture best practices by isolating metadata read operations from write/execution operations and centralizing application permission management in IAM rather than relying on double-filtering access scopes.
Grant developers roles/compute.securityAdmin on the project, assign iam.serviceAccounts.actAs directly to developers on the project root, and disable the metadata server via firewall rules.
Grant developers the predefined roles/compute.instanceAdmin.v1 and roles/iam.serviceAccountUser roles at the project level, and configure VM instances with the restricted https://www.googleapis.com/auth/compute.readonly access scope.