List of questions
Related questions
Question 148 - Professional Cloud DevOps Engineer discussion
You are designing a new Google Cloud organization for a client. Your client is concerned with the risks associated with long-lived credentials created in Google Cloud. You need to design a solution to completely eliminate the risks associated with the use of JSON service account keys while minimizing operational overhead. What should you do?
A.
Use custom versions of predefined roles to exclude all iam.serviceAccountKeys. * service account role permissions.
B.
Apply the constraints/iam.disableserviceAccountKeycreation constraint to the organization.
C.
Apply the constraints/iam.disableServiceAccountKeyUp10ad constraint to the organization.
D.
Grant the roles/ iam.serviceAccountKeyAdmin IAM role to organization administrators only.
Your answer:
0 comments
Sorted by
Leave a comment first