Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise organization is deploying Workload Identity Federation across multiple external continuous integration (CI/CD) platforms to access Google Cloud resources securely. The security team needs to establish a comprehensive security and auditing baseline for the federation lifecycle.
The implementation must satisfy two primary requirements:
Which configuration strategy should the security engineer implement?
Rely on standard Admin Activity audit logs for IAM, configure workforce identity pool session lengths to 15 minutes, and map the external subject claim directly to user email addresses.
Enable Data Access audit logs for the Security Token Service API and IAM API across workload identity pool projects, restrict the IAM Workload Identity Pool Admin role to a dedicated management project, and map only immutable, authoritative provider claims.
Create service account keys for each CI/CD runner, store them in a HashiCorp Vault cluster, and deploy Cloud Functions to revoke and rotate the JSON keys on an hourly schedule.
Assign the Owner role on workload identity pool providers to developers, map the external subject to the issuer URL, and configure Cloud Storage Bucket Lock on audit sinks.
Rely on standard Admin Activity audit logs for IAM, configure workforce identity pool session lengths to 15 minutes, and map the external subject claim directly to user email addresses.
Enable Data Access audit logs for the Security Token Service API and IAM API across workload identity pool projects, restrict the IAM Workload Identity Pool Admin role to a dedicated management project, and map only immutable, authoritative provider claims.
This strategy establishes an end-to-end security architecture for Workload Identity Federation (WIF) by combining deep audit logging with strict administrative boundaries and immutable claim mappings.
sts.googleapis.com). Enabling Data Access audit logs ensures that every token exchange event—along with its mapped external attributes—is permanently captured.GenerateAccessToken are recorded in Identity and Access Management (IAM) API Data Access logs, providing an unbroken audit trail back to the originating external identity even when downstream resource APIs do not natively populate serviceAccountDelegationInfo.roles/iam.workloadIdentityPoolAdmin role, preventing unauthorized actors from inheriting iam.googleapis.com/workloadIdentityPoolProviders.update permissions from parent folders.Create service account keys for each CI/CD runner, store them in a HashiCorp Vault cluster, and deploy Cloud Functions to revoke and rotate the JSON keys on an hourly schedule.
Assign the Owner role on workload identity pool providers to developers, map the external subject to the issuer URL, and configure Cloud Storage Bucket Lock on audit sinks.