New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Google Cloud Certified - Professional Cloud Security Engineer Professional-Cloud-Security-Engineer Question # 78 Topic 8 Discussion

Google Cloud Certified - Professional Cloud Security Engineer Professional-Cloud-Security-Engineer Question # 78 Topic 8 Discussion

Professional-Cloud-Security-Engineer Exam Topic 8 Question 78 Discussion:
Question #: 78
Topic #: 8

Your organization needs to allow public web applications to upload files to a Cloud Storage bucket. You need to design a secure access mechanism that adheres to the principle of least privilege. What should you do?


A.

Create a service account with write access to the Cloud Storage bucket. Distribute the service account key to the external web applications.


B.

Implement a proxy service that authenticates the external web applications and then uploads the files to the Cloud Storage bucket on their behalf using a service account key.


C.

Grant the external web applications direct access to the Cloud Storage bucket by adding their IP addresses to the bucket's access control list (ACL).


D.

Generate short-lived credentials in Workload Identity Federation for each upload request. Grant temporary and scoped access to the Cloud Storage bucket.


Get Premium Professional-Cloud-Security-Engineer Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.