exam questions

Exam Professional Cloud Security Engineer All Questions

View all questions & answers for the Professional Cloud Security Engineer exam

Exam Professional Cloud Security Engineer topic 1 question 213 discussion

Actual exam question from Google's Professional Cloud Security Engineer
Question #: 213
Topic #: 1
[All Professional Cloud Security Engineer Questions]

Your organization is using GitHub Actions as a continuous integration and delivery (CI/CD) platform. You must enable access to Google Cloud resources from the CI/CD pipelines in the most secure way.

What should you do?

  • A. Create a service account key, and add it to the GitHub pipeline configuration file.
  • B. Create a service account key, and add it to the GitHub repository content.
  • C. Configure a Google Kubernetes Engine cluster that uses Workload Identity to supply credentials to GitHub.
  • D. Configure workload identity federation to use GitHub as an identity pool provider.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Pime13
4 months, 2 weeks ago
Selected Answer: D
https://cloud.google.com/blog/products/identity-security/enabling-keyless-authentication-from-github-actions
upvoted 1 times
...
ArizonaClassics
8 months ago
The most secure way to enable access to Google Cloud resources from CI/CD pipelines using GitHub Actions is: D. Configure workload identity federation to use GitHub as an identity pool provider. Workload Identity Federation allows you to configure Google Cloud to trust external identity providers. In this case, GitHub Actions can be set up as an identity pool provider, so you can federate identities between GitHub and Google Cloud. This eliminates the need to create and manage service account keys, which is generally considered less secure and requires more operational overhead like key rotation. With workload identity federation, the process is more secure and streamlined.
upvoted 1 times
...
cyberpunk21
8 months, 1 week ago
Selected Answer: D
D is correct
upvoted 2 times
...
Mithung30
8 months, 3 weeks ago
Selected Answer: D
D is correct. https://cloud.google.com/blog/products/identity-security/enabling-keyless-authentication-from-github-actions
upvoted 2 times
...
pfilourenco
8 months, 4 weeks ago
Selected Answer: D
D is the correct.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago