Google Cloud Certified - Professional Cloud Security Engineer Professional-Cloud-Security-Engineer Question # 43 Topic 5 Discussion

Google Cloud Certified - Professional Cloud Security Engineer Professional-Cloud-Security-Engineer Question # 43 Topic 5 Discussion

Professional-Cloud-Security-Engineer Exam Topic 5 Question 43 Discussion:
Question #: 43
Topic #: 5

A batch job running on Compute Engine needs temporary write access to a Cloud Storage bucket. You want the batch job to use the minimum permissions necessary to complete the task. What should you do?


A.

Create a service account with full Cloud Storage administrator permissions. Assign the service account to the Compute Engine instance.


B.

Grant the predefined storage.objectcreator role to the Compute Engine instances default service account.


C.

Create a service account and embed a long-lived service account key file that has write permissions specified directly in the batch job

script.


D.

Create a service account with the storage .objectcreator role. Use service account impersonation in the batch job's code.


Get Premium Professional-Cloud-Security-Engineer Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.