Professional Cloud Security EngineerConfiguring access within a cloud solution environmentHard
A security engineer is tasked with implementing a policy where a specific service account, `ci-cd-runner@my-project.iam.gserviceaccount.com`, should only be able to deploy resources to a GKE cluster during business hours (9 AM to 5 PM UTC) on weekdays. How can this time-based restriction be enforced?
- AUse an IAM Condition with a time-based expression on the relevant IAM policy binding.
- BApply an Organization Policy constraint to restrict service account usage by time.
- CConfigure a Cloud Scheduler job to enable/disable the service account daily.
- DImplement a custom Cloud Function to intercept and deny deployments outside business hours.
Show answer & explanationAnswer & explanation
Correct answer: A. Use an IAM Condition with a time-based expression on the relevant IAM policy binding.
IAM Conditions allow you to grant roles conditionally, including based on time. A time-based condition using `request.time` and `request.duration` or `request.path` can be configured on the IAM policy binding for the service account, restricting its permissions to specific time windows and days of the week.
Why the other options are wrong
- B. Organization Policies enforce broad constraints across an organization but don't provide the granular, per-binding time-based conditions needed for a specific service account's role.
- C. Manually enabling/disabling a service account with Cloud Scheduler is complex, prone to race conditions, and not a direct IAM enforcement mechanism.
- D. Implementing a custom Cloud Function adds complexity and latency, and it's a reactive solution rather than a proactive IAM enforcement.
IAM Conditions (Time-based)
A Google Cloud IAM feature that allows you to define conditional role bindings, where access is granted only if certain criteria, such as specific time windows, are met.
- Uses Common Expression Language (CEL) for condition expressions.
- Can restrict access based on date, time, IP address, resource tags, etc.
- Applied directly to an IAM policy binding.
Memory trick: Conditions Control Current Clock.