Professional Data EngineerBuilding and operationalizing data processing systemsEasy
A data engineer is implementing a custom data processing job on Compute Engine. This job needs to access sensitive customer data stored in Cloud Storage. To ensure secure access, the engineer wants to grant the Compute Engine VM only the necessary permissions and avoid storing credentials directly on the VM. Which Google Cloud security feature should be configured for the Compute Engine instance?
- ANetwork Tags
- BSSH Key
- CService Account
- DAPI Key
Show answer & explanationAnswer & explanation
Correct answer: C. Service Account
A service account is a special type of Google account that an application or a VM instance can use to make authorized API calls. By assigning a service account with specific IAM roles (e.g., Storage Object Viewer) to the Compute Engine VM, the VM gains the necessary permissions to access Cloud Storage without requiring explicit credentials stored on the instance, adhering to the principle of least privilege.
Why the other options are wrong
- A. Network tags are used for applying firewall rules and network configurations to VMs, not for managing access permissions to Google Cloud services.
- B. SSH keys are used for secure remote access to a VM instance, not for granting the VM itself permissions to other Google Cloud services.
- D. API keys are used for authenticating requests to public APIs, not for granting service-to-service permissions within Google Cloud, and they are less secure than service accounts.
Google Cloud Service Account
A special type of Google account that represents a non-human user, used by applications and VMs to authenticate and authorize access to Google Cloud resources.
- Represents a resource's identity (e.g., VM, App Engine app)
- Grants permissions via IAM roles
- Eliminates need for storing credentials on compute resources
Memory trick: Service accounts: The trusted ID badge for your cloud machines.