Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise operates automated, long-running data processing pipelines deployed across Compute Engine instances and Google Kubernetes Engine (GKE) clusters. These workloads continuously ingest data from Cloud Storage buckets and write analytics results into BigQuery datasets without end-user interaction. The security team previously discovered that some pipelines failed because they relied on human developer credentials that were suspended during employee offboarding.
Which identity architecture should the organization implement to ensure stable, long-term authorization independent of user account lifecycles while enforcing the principle of least privilege?
Rely on the Compute Engine default service account across all VMs and GKE nodes with its default Editor role to handle API authorization across projects.
Generate user-managed service account JSON keys with the Owner role, store them in the VM filesystem, and pass the keys into container environment variables.
Create individual Cloud Identity corporate user accounts for each automated workload, bypass multi-factor authentication policies, and assign them project-level IAM roles.
Provision dedicated user-managed service accounts for each workload, attach them to the Compute Engine instances, configure Workload Identity Federation for GKE pods, and assign granular IAM roles.
Rely on the Compute Engine default service account across all VMs and GKE nodes with its default Editor role to handle API authorization across projects.
Generate user-managed service account JSON keys with the Owner role, store them in the VM filesystem, and pass the keys into container environment variables.
Create individual Cloud Identity corporate user accounts for each automated workload, bypass multi-factor authentication policies, and assign them project-level IAM roles.
Provision dedicated user-managed service accounts for each workload, attach them to the Compute Engine instances, configure Workload Identity Federation for GKE pods, and assign granular IAM roles.
Google Cloud service accounts provide dedicated, non-human identities designed specifically for applications, automated processes, and long-running compute workloads. When workloads run on Google-managed compute infrastructure such as Compute Engine or Google Kubernetes Engine (GKE), service accounts serve as the identity foundation that decouples application access from human user accounts and interactive sign-in flows.
roles/storage.objectViewer and roles/bigquery.dataEditor), preventing excessive access sprawl.This approach aligns with Google Cloud's established security best practices for automated workloads, ensuring high availability, zero dependence on human credentials, and fine-grained access control.