Professional Cloud Security EngineerConfiguring access within a cloud solution environmentHard
A developer needs to create a temporary service account for a CI/CD pipeline that will deploy a new application to a specific GKE cluster. The service account should exist only for the duration of the pipeline execution (maximum 30 minutes) and then be automatically deleted. Which Google Cloud IAM feature allows for the creation of short-lived, ephemeral credentials for this purpose?
- AShort-lived service account credentials API (`generateAccessToken`).
- BService Account Key creation with an expiration date.
- CWorkload Identity Federation with an external IdP.
- DIAM Conditions with a time-based restriction on the service account.
Show answer & explanationAnswer & explanation
Correct answer: A. Short-lived service account credentials API (`generateAccessToken`).
The `generateAccessToken` method of the IAM Service Account Credentials API allows you to programmatically create short-lived OAuth 2.0 access tokens for a service account. These tokens can have a maximum lifetime of 12 hours, but can be generated with a much shorter duration, making them ideal for ephemeral CI/CD pipeline executions without managing long-lived keys.
Why the other options are wrong
- B. Service account keys `(JSON/P12)` are long-lived credentials and do not have an inherent 'expiration date' that automatically deletes them. While you can delete them manually, it's not automatic or short-lived by default.
- C. Workload Identity Federation is for federating *external* identities to Google Cloud, not for generating short-lived credentials for a *Google Cloud service account* itself.
- D. IAM Conditions apply to *when* a role binding is effective, not to the lifetime of the service account itself or its generated credentials.
Short-Lived Service Account Credentials
Temporary, time-bound access tokens generated for a Google Cloud service account, used to access Google Cloud resources without needing long-lived service account keys.
- Generated via the `generateAccessToken` API.
- Ideal for CI/CD, ephemeral workloads, and enhanced security.
- Reduces the risk associated with compromised long-lived keys.
Memory trick: Generate Access Token, Go Quickly.