Cloud Engineer Security & Identity Management Flashcards
6 cards from real Cloud Engineer practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Cloud Engineer Security & Identity Management flashcards as text
Which Google Cloud IAM role grants a user read-only access to all GCP resources within a project?
Answer: roles/viewer
The roles/viewer primitive role grants read-only access to all resources in a project without the ability to modify state.
What is the recommended method to grant a Compute Engine VM access to Google Cloud APIs without storing credentials in the code?
Answer: Attach a service account to the VM instance
Attaching a service account to a VM instance allows it to authenticate to Google Cloud APIs using Application Default Credentials without managing key files.
Which Google Cloud feature allows you to define a perimeter around sensitive GCP resources to prevent data exfiltration?
Answer: VPC Service Controls
VPC Service Controls creates security perimeters around GCP resources to restrict access and mitigate data exfiltration risks.
When should you use Workload Identity Federation instead of a service account key for external workloads?
Answer: When the workload runs outside Google Cloud and you want keyless authentication
Workload Identity Federation allows external workloads (e.g., on AWS or on-premises) to authenticate to GCP without service account keys by exchanging short-lived credentials.
Which principle should guide how IAM permissions are assigned to minimize security risk?
Answer: Least privilege
The principle of least privilege means granting only the minimum permissions necessary for a user or service account to perform its required tasks.
What does Identity-Aware Proxy (IAP) protect in Google Cloud?
Answer: Controls access to applications and VMs based on user identity and context
IAP enforces access control for web applications and VM SSH/RDP by verifying user identity and device context before granting access.