Professional Cloud Security EngineerConfiguring access within a cloud solution environmentMedium

A development team is building an application that needs to retrieve sensitive configuration parameters from Secret Manager. For security reasons, the access to these secrets should only be allowed during specific business hours (9 AM to 5 PM, Monday to Friday UTC). Which Google Cloud IAM feature can enforce this time-based access control for the service account accessing Secret Manager?

  1. AOrganization Policy Constraints
  2. BAccess Approval
  3. CIAM Conditions
  4. DVPC Service Controls
Show answer & explanation

Correct answer: C. IAM Conditions

IAM Conditions allow you to define conditional role bindings based on attributes like time, IP address, or resource tags. This feature is perfect for enforcing time-based access control, ensuring the service account can only retrieve secrets during specified business hours.

Why the other options are wrong

  • A. Organization Policy Constraints enforce rules across an organization (e.g., disallowing certain resource types), but they are not designed for time-based access control on specific IAM role bindings.
  • B. Access Approval is for approving Google support access to customer data, not for time-based access control for service accounts.
  • D. VPC Service Controls define security perimeters and restrict data exfiltration, but they don't provide time-based access control for IAM roles.

IAM Conditions (Time-based)

IAM Conditions allow you to grant roles conditionally, based on specified attributes like time of day, IP address, or resource tags, enabling fine-grained, dynamic access control.

  • Adds conditional logic to IAM policies.
  • Supports `request.time` for time-based access.
  • Enhances least privilege by limiting access context.

Memory trick: Conditions define when the key works.

More Configuring access within a cloud solution environment questions