
Ultimate access to all questions.
You are running applications outside of Google Cloud that need to access Google Cloud resources. You are using Workload Identity Federation to grant external identities IAM roles, avoiding the maintenance and security burden of service account keys. You must protect against identity spoofing and unauthorized access.
What should you do? (Choose two.)
A
Enable data access logs for IAM APIs.
B
Limit the number of external identities that can impersonate a service account.
C
Use a dedicated project to manage workload identity pools and providers.
D
Use immutable attributes in attribute mappings.
E
Limit the resources that a service account can access.