certslothcertsloth
PCDEV/Topic 02

Google Cloud / Professional

Application identity and secure delivery

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: No embedded keys; authorize every boundary.

Must remember

  • Application Default Credentials locate credentials from the execution environment; they are not a permission grant. Use attached service accounts in managed runtimes and Workload Identity Federation for supported external/Kubernetes identities.
  • Use OAuth access tokens for supported APIs and audience-bound ID tokens for authenticated service invocation where required. Verify JWT issuer, audience, expiry and signature rather than only decoding it.
  • Secret Manager stores versioned secrets; Cloud KMS manages cryptographic keys. Rotate credentials with client coordination and grant only the required secret versions/operations.
  • IAP provides identity-aware access to supported applications. Private connectivity, Direct VPC egress, service mesh and Kubernetes NetworkPolicy address different network layers; none replaces application authorization.
  • Scan dependencies and container images with supported artifact/security tools. Binary Authorization can enforce deployment policies based on attestations and trusted build evidence.
  • Use organization and retention policies intentionally, constrain service identities, and validate input/output at every external boundary. AI-generated code and MCP tools require the same review and privilege limits as other code.

Choose under exam pressure

Requirement Choice and reason
A CI system outside Google needs short-lived access Workload Identity Federation instead of a downloaded service-account key.
Only approved images may deploy Trusted build attestations and Binary Authorization policy.

Traps

  • ADC does not mean credentials have the correct role.
  • An internal endpoint can still be called by an overprivileged compromised workload.

Active recall

1. What is the difference between Secret Manager and KMS?

One stores secret values; the other manages keys and cryptographic operations.

2. Why check token audience?

A token issued for another service must not be accepted as authorization here.

3. Does a vulnerability scan authorize deployment?

No; policy and risk decisions determine whether the artifact is acceptable.

4. What protects pod-to-pod traffic boundaries?

Supported Kubernetes NetworkPolicies and network design, with identity controls where needed.

5. Why avoid persistent service-account keys?

They are portable long-lived credentials that are difficult to constrain after disclosure.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.