Professional Cloud Security EngineerConfiguring access within a cloud solution environmentHard

A security engineer is tasked with implementing a policy where a specific service account, `ci-cd-runner@my-project.iam.gserviceaccount.com`, should only be able to deploy resources to a GKE cluster during business hours (9 AM to 5 PM UTC) on weekdays. How can this time-based restriction be enforced?

  1. AUse an IAM Condition with a time-based expression on the relevant IAM policy binding.
  2. BApply an Organization Policy constraint to restrict service account usage by time.
  3. CConfigure a Cloud Scheduler job to enable/disable the service account daily.
  4. DImplement a custom Cloud Function to intercept and deny deployments outside business hours.
Show answer & explanation

Correct answer: A. Use an IAM Condition with a time-based expression on the relevant IAM policy binding.

IAM Conditions allow you to grant roles conditionally, including based on time. A time-based condition using `request.time` and `request.duration` or `request.path` can be configured on the IAM policy binding for the service account, restricting its permissions to specific time windows and days of the week.

Why the other options are wrong

  • B. Organization Policies enforce broad constraints across an organization but don't provide the granular, per-binding time-based conditions needed for a specific service account's role.
  • C. Manually enabling/disabling a service account with Cloud Scheduler is complex, prone to race conditions, and not a direct IAM enforcement mechanism.
  • D. Implementing a custom Cloud Function adds complexity and latency, and it's a reactive solution rather than a proactive IAM enforcement.

IAM Conditions (Time-based)

A Google Cloud IAM feature that allows you to define conditional role bindings, where access is granted only if certain criteria, such as specific time windows, are met.

  • Uses Common Expression Language (CEL) for condition expressions.
  • Can restrict access based on date, time, IP address, resource tags, etc.
  • Applied directly to an IAM policy binding.

Memory trick: Conditions Control Current Clock.

More Configuring access within a cloud solution environment questions