ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 95 - Professional Cloud Security Engineer discussion

Report
Export

You are a Security Administrator at your organization. You need to restrict service account creation capability within production environments. You want to accomplish this centrally across the organization. What should you do?

A.
Use Identity and Access Management (IAM) to restrict access of all users and service accounts that have access to the production environment.
Answers
A.
Use Identity and Access Management (IAM) to restrict access of all users and service accounts that have access to the production environment.
B.
Use organization policy constraints/iam.disableServiceAccountKeyCreation boolean to disable the creation of new service accounts.
Answers
B.
Use organization policy constraints/iam.disableServiceAccountKeyCreation boolean to disable the creation of new service accounts.
C.
Use organization policy constraints/iam.disableServiceAccountKeyUpload boolean to disable the creation of new service accounts.
Answers
C.
Use organization policy constraints/iam.disableServiceAccountKeyUpload boolean to disable the creation of new service accounts.
D.
Use organization policy constraints/iam.disableServiceAccountCreation boolean to disable the creation of new service accounts.
Answers
D.
Use organization policy constraints/iam.disableServiceAccountCreation boolean to disable the creation of new service accounts.
Suggested answer: D

Explanation:

You can use the iam.disableServiceAccountCreation boolean constraint to disable the creation of new service accounts. This allows you to centralize management of service accounts while not restricting the other permissions your developers have on projects. https://cloud.google.com/resource-manager/docs/organization-policy/restricting-service-accounts#disable_service_account_creation

asked 18/09/2024
Simon Sawal
31 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first