exam questions

Exam Professional Cloud Security Engineer All Questions

View all questions & answers for the Professional Cloud Security Engineer exam

Exam Professional Cloud Security Engineer topic 1 question 95 discussion

Actual exam question from Google's Professional Cloud Security Engineer
Question #: 95
Topic #: 1
[All Professional Cloud Security Engineer Questions]

You are a Security Administrator at your organization. You need to restrict service account creation capability within production environments. You want to accomplish this centrally across the organization. What should you do?

  • A. Use Identity and Access Management (IAM) to restrict access of all users and service accounts that have access to the production environment.
  • B. Use organization policy constraints/iam.disableServiceAccountKeyCreation boolean to disable the creation of new service accounts.
  • C. Use organization policy constraints/iam.disableServiceAccountKeyUpload boolean to disable the creation of new service accounts.
  • D. Use organization policy constraints/iam.disableServiceAccountCreation boolean to disable the creation of new service accounts.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Tabayashi
Highly Voted 2 years ago
Answer is (D). You can use the iam.disableServiceAccountCreation boolean constraint to disable the creation of new service accounts. This allows you to centralize management of service accounts while not restricting the other permissions your developers have on projects. https://cloud.google.com/resource-manager/docs/organization-policy/restricting-service-accounts#disable_service_account_creation
upvoted 11 times
...
[Removed]
Highly Voted 9 months, 1 week ago
Selected Answer: D
"D" Refreshing tabayashi's comment. https://cloud.google.com/resource-manager/docs/organization-policy/restricting-service-accounts#disable_service_account_creation
upvoted 5 times
...
TNT87
Most Recent 1 year ago
Selected Answer: D
Answer D You can use the iam.disableServiceAccountCreation boolean constraint to disable the creation of new service accounts. This allows you to centralize management of service accounts while not restricting the other permissions your developers have on projects.
upvoted 1 times
...
pskm12
1 year, 3 months ago
In the question, it is clearly mentioned that -> You want to accomplish this centrally across the organization. So, it would obviously be D
upvoted 1 times
...
gupta3
1 year, 4 months ago
Selected Answer: A
Are they not conflicting - restricting service account creation capability within production environments & enforcing policy across Org ?
upvoted 1 times
...
AzureDP900
1 year, 6 months ago
D is correct
upvoted 2 times
...
AwesomeGCP
1 year, 6 months ago
Selected Answer: D
D. Use organization policy constraints/iam.disableServiceAccountCreation boolean to disable the creation of new service accounts.
upvoted 2 times
...
zellck
1 year, 7 months ago
Selected Answer: D
D is the answer.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago