Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

Exam Professional-Cloud-DevOps-Engineer All Questions
Exam Professional-Cloud-DevOps-Engineer All Questions

View all questions & answers for the Professional-Cloud-DevOps-Engineer exam

Google Cloud DevOps Engineer Professional-Cloud-DevOps-Engineer Question # 7 Topic 1 Discussion

Professional-Cloud-DevOps-Engineer Exam Topic 1 Question 7 Discussion:
Question #: 7
Topic #: 1

You are designing a new Google Cloud organization for a client. Your client is concerned with the risks associated with long-lived credentials created in Google Cloud. You need to design a solution to completely eliminate the risks associated with the use of JSON service account keys while minimizing operational overhead. What should you do?


A.

Use custom versions of predefined roles to exclude all iam.serviceAccountKeys. * service account role permissions.


B.

Apply the constraints/iam.disableserviceAccountKeycreation constraint to the organization.


C.

Apply the constraints/iam. disableServiceAccountKeyUp10ad constraint to the organization.


D.

Grant the roles/ iam.serviceAccountKeyAdmin IAM role to organization administrators only.


Get Premium Professional-Cloud-DevOps-Engineer Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.