Cloud Engineer Security & Identity Management Flashcards
6 cards from real Cloud Engineer practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Cloud Engineer Security & Identity Management flashcards as text
Which Google Cloud service stores and manages sensitive configuration data such as API keys, passwords, and certificates?
Answer: Secret Manager
Secret Manager provides a secure and convenient way to store, access, and manage sensitive data like API keys and passwords with versioning and access control.
What is the best practice for granting temporary elevated access to a GCP resource for a short-lived task?
Answer: Use IAM Conditions with a time-bounded expression
IAM Conditions allow you to grant time-limited access by adding a date/time attribute expression to a binding, which automatically expires after the specified period.
A GCP project contains a Cloud Run service that needs to read from a Firestore database. What is the most secure way to grant this access?
Answer: Create a dedicated service account with only Firestore read permissions and assign it to the Cloud Run service
Creating a dedicated, least-privilege service account for each service ensures that a compromise of one service does not expose permissions for others.
Which GCP feature lets you restrict which external identities (e.g., from other domains) can be granted IAM roles in your organization?
Answer: Domain restricted sharing (Organization Policy constraint)
The `iam.allowedPolicyMemberDomains` Organization Policy constraint restricts IAM bindings to only identities from specified Cloud Identity or Google Workspace domains.
What type of service account key has an expiration date and is automatically managed by Google Cloud?
Answer: Short-lived credential (e.g., impersonation token)
Short-lived credentials such as access tokens obtained via service account impersonation expire automatically, eliminating the risk of long-lived key exposure.
Which Google Cloud service should you enable to receive alerts when sensitive data is detected in Cloud Storage buckets?
Answer: Cloud DLP (Sensitive Data Protection)
Cloud DLP (now called Sensitive Data Protection) scans data in Cloud Storage, BigQuery, and Datastore for sensitive information like PII or credentials and can trigger notifications.