Ngân hàng đề — Google Cloud Professional Cloud Security Engineer

Tìm thấy 395 câu.

Câu 391
Your company is in a regulated industry that requires low overhead encryption using private connectivity from on-premises data centers to Google Cloud. You need to establish connectivity and ensure high availability across multiple regions. What should you do?
  1. A Set up two pairs of HA VPNs using IPSec from the data centers in multiple regions.
  2. B Set up pairs of Cloud Interconnect connections to your data centers in multiple regions, and employ MACSec encryption.
  3. C Set up L2TP encryption over pairs of dedicated Cloud Interconnect connections from the data centers in multiple regions.
  4. D Set up IPSec encryption over Partner Interconnect connections from your data centers in multiple regions.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào một công ty hoạt động trong ngành công nghiệp được quy định nghiêm ngặt (regulated industry), đòi hỏi mã hóa với chi phí thấp (low overhead encryption) sử dụng kết nối riêng tư (private connectivity) từ các trung tâm dữ liệu tại chỗ (on-premises data centers) đến Google Cloud. Yêu cầu chính là thiết lập kết nối với tính sẵn sàng cao (high availability) trải rộng nhiều vùng (multiple regions).

📌 Các yếu tố then chốt:

  • Private connectivity: Ưu tiên kết nối riêng tư, không qua internet công cộng để đảm bảo bảo mật và độ trễ thấp.
  • Low overhead encryption: Mã hóa phải nhẹ, không tốn nhiều tài nguyên (ví dụ: layer 2 encryption thay vì layer 3 như IPSec).
  • High availability: Sử dụng cặp kết nối dự phòng (pairs) để tránh điểm nghẽn đơn lẻ.
  • Multiple regions: Hỗ trợ đa vùng để tăng độ tin cậy và tuân thủ quy định.
  • Kiến thức cập nhật đến 2026: Dựa trên Google Cloud Networking mới nhất (Dedicated Interconnect v2, MACSec hỗ trợ từ 2021 và ổn định đến 2026), ưu tiên giải pháp hybrid cloud an toàn cho ngành regulated như tài chính, y tế.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Set up pairs of Cloud Interconnect connections to your data centers in multiple regions, and employ MACSec encryption.

🛠️ Lý do chi tiết:

  • Cloud Interconnect (Dedicated Interconnect) cung cấp kết nối riêng tư trực tiếp từ on-premises đến Google Cloud qua đối tác colocation (như Equinix), với băng thông cao (10/100/1000 Gbps), độ trễ thấp, và private hoàn toàn (không qua internet).
  • Pairs of connections: Tạo cặp kết nối dự phòng (redundant) để đảm bảo high availability (99.99% SLA), hỗ trợ multiple regions (multi-region HA).
  • MACSec encryption: Đây là mã hóa Layer 2 (IEEE 802.1AE) với overhead cực thấp (chỉ ~2-4% bandwidth loss), lý tưởng cho regulated industry cần mã hóa end-to-end mà không ảnh hưởng hiệu suất. Hỗ trợ đầy đủ trên Dedicated Interconnect từ 2021, cập nhật đến 2026 với key rotation tự động.
  • Giải pháp này đáp ứng tất cả yêu cầu: private, low overhead, HA, multi-region.

📋 Giải thích tất cả các phương án

Dưới đây là phân tích từng phương án (giữ nguyên văn bản gốc tiếng Anh). Tôi đánh dấu ✅ đúng hoặc ❌ sai, kèm lý do bằng tiếng Việt rõ ràng:

  • ❌ Set up two pairs of HA VPNs using IPSec from the data centers in multiple regions.
    🧨 Sai vì: HA VPN (High Availability VPN) sử dụng IPSec qua internet công cộng, không phải private connectivity thuần túy. IPSec là mã hóa Layer 3 với overhead cao (10-20% bandwidth loss do encapsulation), không phù hợp "low overhead". Dù hỗ trợ multi-region, nhưng không đáp ứng yêu cầu private và hiệu suất cho regulated industry.

  • ✅ Set up pairs of Cloud Interconnect connections to your data centers in multiple regions, and employ MACSec encryption.
    🟢 Đúng vì: Như giải thích ở trên, đây là giải pháp tối ưu với Dedicated Interconnect + MACSec: private, low overhead (~2% loss), HA qua pairs, multi-region. Hoàn hảo cho hybrid cloud an toàn.

  • ❌ Set up L2TP encryption over pairs of dedicated Cloud Interconnect connections from the data centers in multiple regions.
    🔒 Sai vì: L2TP (Layer 2 Tunneling Protocol) không được hỗ trợ chính thức trên Cloud Interconnect (chỉ IPSec hoặc MACSec cho encryption). L2TP thường dùng qua internet, overhead cao hơn MACSec, và không phải lựa chọn chuẩn của Google Cloud cho dedicated connections. Không đảm bảo low overhead thực sự.

  • ❌ Set up IPSec encryption over Partner Interconnect connections from your data centers in multiple regions.
    🌐 Sai vì: Partner Interconnect là kết nối qua đối tác bên thứ ba (không dedicated trực tiếp), có thể qua shared infrastructure, không private 100% như Dedicated. IPSec trên đó là Layer 3 với overhead cao, không low overhead. Dù hỗ trợ multi-region, nhưng kém hơn Dedicated Interconnect + MACSec về bảo mật và hiệu suất.

📘 Tài liệu tham khảo

Hy vọng phân tích này giúp bạn ôn thi chứng chỉ Google Cloud Professional Cloud Security Engineer! 🚀 Nếu cần thêm chi tiết, hãy hỏi nhé!

Câu 392
You manage the security logs within your cloud environment. You have configured a continuous export of security logs to Cloud Storage buckets for long-term retention. You need to provide auditors the ability to analyze the logs that were exported to Cloud Storage. Your solution must be cost-effective and quickly implemented.

What should you do?
  1. A Use a VM instance to download the data from Cloud Storage. Provide the auditors access to the VM and allow them to install their preferred analytics toolset.
  2. B Use the data in the Cloud Storage bucket as an external table in BigQuery. Provide the auditors access to the BigQuery dataset.
  3. C Use Dataflow to import the data from Cloud Storage into Elasticsearch. Provide the auditors with access to Elasticsearch.
  4. D Use a Cloud Run job to import the log data from Cloud Storage to Cloud Logging. Provide the auditors access through Log Analytics.
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi tập trung vào việc quản lý bảo mật logs trong môi trường Google Cloud Platform (GCP). Bạn đã cấu hình xuất logs bảo mật liên tục (continuous export) sang Cloud Storage buckets để lưu trữ dài hạn. Nhiệm vụ là cung cấp cho auditors (kiểm toán viên) khả năng phân tích logs đã xuất ra, với yêu cầu giải pháp phải tiết kiệm chi phí (cost-effective) và triển khai nhanh chóng (quickly implemented).

🔍 Yêu cầu chính cần đáp ứng:

  • Auditors cần truy cập và phân tích dữ liệu logs mà không cần di chuyển dữ liệu (để tránh chi phí lưu trữ/transfer cao).
  • Giải pháp phải an toàn, dễ quản lý quyền truy cập, và phù hợp với best practices của GCP Security (như IAM cho auditors).
  • Không nên tốn kém về compute/storage mới hoặc thời gian setup phức tạp.

📘 Bối cảnh cập nhật 2026: Theo tài liệu GCP mới nhất (Google Cloud Logging và BigQuery docs, cập nhật Q1/2026), continuous export logs sang Cloud Storage là chuẩn cho retention dài hạn (>400 ngày miễn phí), và BigQuery hỗ trợ external tables để query trực tiếp mà không copy dữ liệu.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Use the data in the Cloud Storage bucket as an external table in BigQuery. Provide the auditors access to the BigQuery dataset.

Lý do chi tiết 🛠️:

  • Tiết kiệm chi phí: External table cho phép query trực tiếp trên dữ liệu Cloud Storage mà không cần copy/import (chỉ tính phí query BigQuery, ~$5/TB scanned – rẻ hơn nhiều so với ETL jobs).
  • Triển khai nhanh: Tạo external table chỉ mất vài phút qua console/CLI/gcloud (gcloud bigquery tables create --external_table_definition).
  • Phù hợp auditors: Auditors chỉ cần quyền BigQuery Data Viewer trên dataset qua IAM – an toàn, không cần VM/Elasticsearch phức tạp.
  • Tích hợp logs: Logs JSON từ Cloud Storage tự động parse được trong BigQuery (hỗ trợ schema auto-detect từ 2024).
  • Best practice Security: Giữ nguyên immutable storage ở CS, query serverless, audit trails đầy đủ.

📋 Phân tích tất cả các phương án

Dưới đây là phân tích từng lựa chọn một cách chi tiết, với văn bản gốc giữ nguyên tiếng Anh. Mỗi phương án được đánh giá dựa trên cost, implementation time, security và phù hợp yêu cầu.

  • Use a VM instance to download the data from Cloud Storage. Provide the auditors access to the VM and allow them to install their preferred analytics toolset.
    ❌ Sai vì:
    Giải pháp này không tiết kiệm chi phí (VM chạy liên tục tốn ~$50/tháng + egress fees khi download), triển khai chậm (provision VM, IAM, firewall rules, install tools mất hàng giờ/ngày). Auditors cần quyền VM rộng (SSH/RDP) – rủi ro bảo mật cao (privilege escalation). Không scalable cho logs lớn (TB/PB). Không phải best practice GCP (thay vào đó dùng serverless).

  • Use the data in the Cloud Storage bucket as an external table in BigQuery. Provide the auditors access to the BigQuery dataset.
    ✅ Đúng vì:
    Như đã giải thích ở trên: Serverless query, zero-copy data, cost chỉ query-based, setup nhanh (CLI 1 lệnh), quyền truy cập granular qua IAM. Hoàn hảo cho auditors phân tích SQL-based trên logs (e.g., filter threats, compliance reports). Hỗ trợ partitioning/columnar cho perf cao.

  • Use Dataflow to import the data from Cloud Storage into Elasticsearch. Provide the auditors with access to Elasticsearch.
    ❌ Sai vì:
    Chi phí cao (Dataflow compute ~$0.01/vCPU-hour + Elasticsearch Managed Service ~$100/cluster/tháng), triển khai phức tạp (pipeline code, schema mapping, takes days). Elasticsearch không native cho GCP logs (cần Elastic Stack setup), auditors cần quyền Kibana – khó manage security (roles/auth). Không "quickly implemented" và dư thừa cho analysis đơn giản.

  • Use a Cloud Run job to import the log data from Cloud Storage to Cloud Logging. Provide the auditors access through Log Analytics.
    ❌ Sai vì:
    Không hợp lý: Cloud Logging chỉ retention 400 ngày miễn phí/mức cao hơn tốn phí; import ngược lại từ CS sang Logging mất chi phí storage kép và thời gian ETL (Cloud Run job trigger cần code/container). Log Analytics (trong Logging UI) kém mạnh cho analysis lớn so BigQuery (no SQL flexibility). Auditors chỉ view dashboard cơ bản – không đủ cho deep analysis, vi phạm "cost-effective/quick".

📚 Tài liệu tham khảo (cập nhật 2026)

Giải pháp này đảm bảo tuân thủ CIS GCP Benchmarks và zero-trust access! 🚀

Câu 393
Your organization currently uses a third-party identity provider (IdP) that only requires a username and password for authentication. You need to enforce 2-step verification (2SV) for the Super admins in Cloud Identity. What should you do?
  1. A Create an organizational unit (OU) for Super admins, and enable 2SV within Cloud Identity for the OU.
  2. B Collaborate with the third-party IdP to enable 2SV for Super admins while maintaining the current Cloud Identity configuration.
  3. C Implement monitoring tools to track the authentication methods used by Super admins in Cloud Identity. Alert on those not using 2SV.
  4. D Evaluate the 2SV options for Super admins offered by both the third-party IdP and Cloud Identity. Implement the solution that provides the strongest second factor.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi này thuộc lĩnh vực quản lý danh tính và truy cập (Identity and Access Management - IAM) trong Google Cloud Identity (một phần của Google Cloud Platform - GCP). Tổ chức đang sử dụng third-party Identity Provider (IdP) bên thứ ba (ví dụ: Okta, Azure AD, hoặc các IdP SAML/OIDC khác) chỉ hỗ trợ xác thực bằng username và password (không có 2-Step Verification - 2SV). Nhiệm vụ là enforce (áp dụng bắt buộc) 2SV cho Super admins trong Cloud Identity.

Super admins là tài khoản có quyền cao nhất trong Google Workspace/Cloud Identity, có thể quản lý toàn bộ tổ chức. Vì sử dụng external IdP, quy trình xác thực được chuyển hướng đến IdP, nên Cloud Identity không trực tiếp kiểm soát phương thức xác thực ban đầu. Giải pháp cần đảm bảo 2SV mạnh mẽ nhất (second factor như TOTP, hardware key, hoặc push notification), theo best practice bảo mật mới nhất của Google (cập nhật đến 2026: nhấn mạnh multi-factor authentication - MFA với các tiêu chuẩn như FIDO2 cho Super admins).

📘 Tài liệu tham khảo chính:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Evaluate the 2SV options for Super admins offered by both the third-party IdP and Cloud Identity. Implement the solution that provides the strongest second factor.

Lý do:

  • Đây là cách tiếp cận toàn diện và linh hoạt nhất theo hướng dẫn chính thức của Google. Với external IdP, bạn cần đánh giá (evaluate) các tùy chọn 2SV từ cả IdP (ví dụ: enable MFA tại IdP) và Cloud Identity (native 2SV với Google Prompt, security keys). Sau đó, triển khai giải pháp có second factor mạnh nhất (strongest, như FIDO2 hardware keys > TOTP > SMS).
  • Không nên chỉ dựa vào một bên; cách này đảm bảo enforce 2SV mà không phá vỡ federation. Google khuyến nghị kiểm tra compatibility và chọn MFA cấp cao nhất để bảo vệ Super admins (rủi ro cao nhất). Cập nhật 2026: Tích hợp Context-Aware Access (CAA) để enforce thêm dựa trên device/risk.

🛠️ Giải thích tất cả các phương án (đúng/sai)

Dưới đây là phân tích từng lựa chọn, giữ nguyên văn bản gốc tiếng Anh. Mỗi phương án được đánh giá dựa trên tính khả thi, best practice và hạn chế thực tế trong GCP.

  • ❌ [SAI] Create an organizational unit (OU) for Super admins, and enable 2SV within Cloud Identity for the OU.
    Giải thích sai: Việc tạo Organizational Unit (OU) và enable 2SV tại Cloud Identity chỉ áp dụng cho native Google accounts (không dùng external IdP). Với third-party IdP, xác thực được xử lý bởi IdP trước, nên Cloud Identity không thể enforce 2SV (bị bypass). OU hữu ích cho policy scoping nhưng không giải quyết root cause ở IdP. Rủi ro: Super admins vẫn chỉ dùng username/password.

  • ❌ [SAI] Collaborate with the third-party IdP to enable 2SV for Super admins while maintaining the current Cloud Identity configuration.
    Giải thích sai: Hợp tác với IdP để enable 2SV là cần thiết nhưng không đủ toàn diện, vì bỏ qua tùy chọn mạnh hơn từ Cloud Identity (như Google security keys). Cách này chỉ fix một bên, có thể dẫn đến second factor yếu (nếu IdP chỉ hỗ trợ SMS). Google không khuyến nghị "maintain current config" mà yêu cầu evaluate cả hai để chọn strongest.

  • ❌ [SAI] Implement monitoring tools to track the authentication methods used by Super admins in Cloud Identity. Alert on those not using 2SV.
    Giải thích sai: Monitoring (qua Cloud Audit Logs hoặc Security Command Center) chỉ phát hiện (detect) chứ không enforce (bắt buộc) 2SV. Super admins có thể bỏ qua alert, dẫn đến rủi ro bảo mật cao. Đây là reactive approach, không phải proactive enforcement theo nguyên tắc Zero Trust (cập nhật 2026).

  • ✅ [ĐÚNG] Evaluate the 2SV options for Super admins offered by both the third-party IdP and Cloud Identity. Implement the solution that provides the strongest second factor.
    Giải thích đúng: Như đã nêu ở trên, cách này tối ưu hóa bảo mật bằng đánh giá toàn bộ options (IdP MFA vs. Cloud Identity 2SV), chọn strongest factor (phù hợp NIST/FIDO standards). Hỗ trợ hybrid setup, dễ migrate nếu cần. Đảm bảo compliance với GCP security baselines.

🛡️ Lời khuyên bổ sung: Sau khi implement, kết hợp với Privileged Access Management (PAM) như Just-In-Time access và ngắt Super admin rights định kỳ để tăng cường bảo mật!

Câu 394
Your organization has a hybrid cloud environment with a data center connected to Google Cloud through a dedicated Cloud Interconnect connection. You need to configure private access from your on-premises hosts to Google APIs, specifically Cloud Storage and BigQuery, without exposing traffic to the public internet. What should you do?
  1. A Configure Shared VPC to extend your Google Cloud VPC network to your on-premises environment. Use Private Google Access to access Google APIs.
  2. B Establish VPC peering between your on-premises network and your Google Cloud VPC network. Configure Cloud Firewall rules to allow traffic to Google API IP ranges.
  3. C Use Private Google Access for on-premises hosts. Configure DNS resolution to point to the private.googleapis.com domain.
  4. D Configure Cloud NAT on your on-premises network. Configure DNS records in a private DNS zone to send requests to 199.36.153.8/30 to access Google APIs.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả một môi trường hybrid cloud nơi data center on-premises được kết nối với Google Cloud qua dedicated Cloud Interconnect (kết nối riêng tư tốc độ cao). Yêu cầu là cấu hình private access từ các host on-premises đến các Google APIs cụ thể như Cloud Storage và BigQuery, mà không để traffic đi qua public internet.

📌 Mục tiêu chính: Đảm bảo traffic nội bộ an toàn, sử dụng private IP ranges (như 199.36.153.8/30) để resolve các domain Google APIs (ví dụ: private.googleapis.com), tận dụng kết nối Cloud Interconnect đã có. Đây là tính năng Private Google Access for on-premises hosts (cập nhật mới nhất đến 2026, hỗ trợ hybrid access qua interconnect/partner interconnect mà không cần public egress).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Use Private Google Access for on-premises hosts. Configure DNS resolution to point to the private.googleapis.com domain.

Lý do chi tiết 🛠️:

  • Private Google Access for on-premises hosts (tính năng dành riêng cho hybrid) cho phép host on-premises resolve và truy cập Google APIs qua private IP (199.36.153.8/30) mà không cần public internet.
  • Cấu hình DNS resolution để trỏ private.googleapis.com (và các subdomain như storage.googleapis.com, bigquery.googleapis.com) về private IP range này.
  • Điều kiện tiên quyết: Kết nối qua Cloud Interconnect hoặc VPN, và enable Private Google Access trên VPC (nhưng không yêu cầu Shared VPC hay peering).
  • Đây là giải pháp chuẩn xác, đơn giản, bảo mật cao nhất theo best practices Google Cloud 2026, tránh NAT/public routing.

📋 Giải thích tất cả các phương án (đúng/sai)

Dưới đây là phân tích từng lựa chọn, giữ nguyên văn bản gốc tiếng Anh:

  • ❌ [SAI] Configure Shared VPC to extend your Google Cloud VPC network to your on-premises environment. Use Private Google Access to access Google APIs.
    Giải thích sai: Shared VPC dùng để chia sẻ subnet giữa các project VPC trong Google Cloud, không extend trực tiếp đến on-premises. Không hỗ trợ hybrid access từ on-premises hosts; Private Google Access chỉ hoạt động nội bộ VPC, không giải quyết DNS resolution cho on-premises.

  • ❌ [SAI] Establish VPC peering between your on-premises network and your Google Cloud VPC network. Configure Cloud Firewall rules to allow traffic to Google API IP ranges.
    Giải thích sai: VPC peering chỉ giữa các VPC Google Cloud (hoặc tương đương), không peering trực tiếp với on-premises network (on-premises không phải VPC). Firewall rules cho IP ranges public/private không thay thế được private access; traffic vẫn có nguy cơ public nếu không resolve đúng.

  • ✅ [ĐÚNG] Use Private Google Access for on-premises hosts. Configure DNS resolution to point to the private.googleapis.com domain.
    Giải thích đúng: Như đã nêu ở phần đáp án đúng. Đây là phương pháp chính thức, hỗ trợ Cloud Storage/BigQuery qua private path trên Interconnect. DNS policy resolve private.googleapis.com → 199.36.153.8/30 tự động.

  • ❌ [SAI] Configure Cloud NAT on your on-premises network. Configure DNS records in a private DNS zone to send requests to 199.36.153.8/30 to access Google APIs.
    Giải thích sai: Cloud NAT là dịch vụ Google Cloud cho outbound từ VPC instances ra internet/private, không deploy trên on-premises. IP 199.36.153.8/30 đúng cho private access nhưng không dùng NAT; DNS zone thủ công không cần thiết vì Private Google Access tự handle resolution.

📘 Tài liệu tham khảo (cập nhật mới nhất 2026)

🔒 Kết luận: Giải pháp đúng đảm bảo zero-trust private access, tuân thủ CIS benchmarks cho hybrid security!

Câu 395
A batch job running on Compute Engine needs temporary write access to a Cloud Storage bucket. You want the batch job to use the minimum permissions necessary to complete the task. What should you do?
  1. A Create a service account with full Cloud Storage administrator permissions. Assign the service account to the Compute Engine instance.
  2. B Create a service account and embed a long-lived service account key file that has write permissions specified directly in the batch job script.
  3. C Create a service account with the storage.objectCreator role. Use service account impersonation in the batch job's code.
  4. D Grant the predefined storage.objectCreator role to the Compute Engine instance's default service account.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào bảo mật và nguyên tắc least privilege (quyền hạn tối thiểu) trong Google Cloud Platform (GCP). Cụ thể:

  • Một batch job (công việc hàng loạt) đang chạy trên Compute Engine (máy ảo GCP) cần quyền ghi tạm thời (temporary write access) vào một Cloud Storage bucket.
  • Yêu cầu chính: Sử dụng minimum permissions necessary (quyền hạn nhỏ nhất để hoàn thành nhiệm vụ), tránh quyền thừa hoặc rủi ro bảo mật lâu dài như key dài hạn.
  • Mục tiêu: Đảm bảo quyền truy cập tạm thời, an toàn, tuân thủ IAM best practices của GCP (cập nhật đến 2026: IAM hỗ trợ impersonation qua OAuth2 tokens ngắn hạn, không khuyến khích service account keys).

Nguyên tắc cốt lõi:

  • Tránh full permissions hoặc long-lived credentials.
  • Ưu tiên service account impersonation để tạo token tạm thời (thường 1 giờ, tự động refresh).
  • Role phù hợp cho write: storage.objectCreator (chỉ tạo object, không đọc/xóa).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Create a service account with the storage.objectCreator role. Use service account impersonation in the batch job's code.

Lý do:

  • 🛡️ Least privilege: Role storage.objectCreator chỉ cho phép tạo object (write), không đọc/xóa, phù hợp minimum permissions.
  • 🔄 Temporary access: Impersonation sử dụng OAuth2 access token ngắn hạn (tự động trong code, ví dụ qua Google Auth library), không cần lưu key file.
  • 📱 Cách triển khai: Tạo SA riêng → Gán role → Trong code batch job (Python/Java/...), dùng google.auth để impersonate SA (e.g., impersonated_credentials = google.auth.impersonated_credentials.ImpersonatedCredentials(...)).
  • ✅ Best practice 2026: GCP khuyến cáo impersonation thay vì keys (theo Security Command Center và IAM docs), giảm rủi ro key leak.

📋 Giải thích tất cả các phương án

Dưới đây là phân tích từng lựa chọn (giữ nguyên văn bản gốc tiếng Anh), với lý do đúng/sai dựa trên GCP IAM mới nhất:

  • Create a service account with full Cloud Storage administrator permissions. Assign the service account to the Compute Engine instance.
    ❌ Sai: Role roles/storage.admin cấp full quyền (read/write/delete/manage), vi phạm least privilege. Gán SA cho toàn instance ảnh hưởng tất cả workload, không temporary, tăng rủi ro privilege escalation.

  • Create a service account and embed a long-lived service account key file that has write permissions specified directly in the batch job script.
    ❌ Sai: Service account key long-lived (không expire tự động), dễ leak nếu script bị lộ. GCP cấm khuyến khích keys từ 2021 (Workload Identity Federation thay thế), vi phạm security hygiene 2026.

  • Create a service account with the storage.objectCreator role. Use service account impersonation in the batch job's code.
    ✅ Đúng: Như giải thích trên – minimum role + temporary impersonation token, an toàn và scalable cho batch job.

  • Grant the predefined storage.objectCreator role to the Compute Engine instance's default service account.
    ❌ Sai: Default SA (compute-engine-default) thường có quyền rộng (e.g., roles/editor), grant thêm làm quyền instance-level vĩnh viễn, không temporary cho batch job cụ thể. Khó thu hồi, vi phạm separation of duties.

📘 Tài liệu tham khảo (cập nhật GCP 2026)

🛡️ Kết luận: Lựa chọn đúng đảm bảo zero-trust security với temporary credentials, phù hợp chứng chỉ Professional Cloud Security Engineer!