Google Associate Cloud EngineerDeploying and implementing a cloud solutionEasy
A developer is writing an application that runs on a Compute Engine instance and needs to securely access data stored in a Cloud Storage bucket in the same project. The application should use the principle of least privilege, and credentials should not be hardcoded. Which method should the developer use to grant access to the Cloud Storage bucket?
- AUse a user-managed encryption key (UME K) for the Cloud Storage bucket.
- BConfigure a VPC Service Controls perimeter around the bucket and VM.
- CAssign the default Compute Engine service account with appropriate Cloud Storage roles.
- DGenerate a service account key and store it on the VM.
Show answer & explanationAnswer & explanation
Correct answer: C. Assign the default Compute Engine service account with appropriate Cloud Storage roles.
Assigning appropriate Cloud Storage roles to the default Compute Engine service account (or a custom service account) is the recommended secure way to grant access, as it leverages instance metadata credentials and avoids hardcoding or managing keys.
Why the other options are wrong
- A. User-managed encryption keys (UME K) are for data encryption, not for granting identity-based access to a Cloud Storage bucket.
- B. VPC Service Controls enhance data exfiltration protection by creating security perimeters, but they do not grant identity-based access to Cloud Storage for a Compute Engine instance.
- D. Generating a service account key and storing it on the VM is less secure as it creates a long-lived credential that needs to be managed and rotated.
Service Accounts for Compute Engine
Special Google Cloud accounts used by applications or Compute Engine instances to make authorized API calls.
- Credentials are automatically managed by Google Cloud (instance metadata).
- Allows granting granular permissions using IAM roles.
- Adheres to the principle of least privilege by assigning only necessary roles.
Memory trick: Service account for secure access, no keys needed.