PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #313
Your organization has hired a small, temporary partner team for 18 months. The temporary team will work alongside your DevOps team to develop your organization's application that is hosted on Google…
The correct answer is B. Create a workforce identity pool and federate the identity pool with the identity provider (IdP) of. https://cloud.google.com/iam/docs/workforce-identity-federation https://cloud.google.com/iam/docs/temporary-elevated-access One way to protect sensitive resources is to limit access to them. However, limiting access to sensitive resources also creates friction for anyone who…
Question
Options
- ACreate a temporary username and password for the temporary partner team members. Auto-
- BCreate a workforce identity pool and federate the identity pool with the identity provider (IdP) of
- CImplement just-in-time privileged access to Google Cloud for the temporary partner team.
- DAdd the identities of the temporary partner team members to your identity provider (IdP).
How the community answered
(49 responses)- A6% (3)
- B78% (38)
- C4% (2)
- D12% (6)
Explanation
https://cloud.google.com/iam/docs/workforce-identity-federation https://cloud.google.com/iam/docs/temporary-elevated-access One way to protect sensitive resources is to limit access to them. However, limiting access to sensitive resources also creates friction for anyone who occasionally needs to access those resources. For example, a user might need break-glass, or emergency, access to sensitive resources to resolve an incident. In these situations, we recommend giving the user permission to access the resource temporarily. We also recommend that, to improve auditing, you record the user's justification for accessing the
Topics
Community Discussion
No community discussion yet for this question.