GCP Associate Cloud Engineer Practice Question

A healthcare company stores sensitive invoices in a Cloud Storage bucket that has both Uniform bucket-level access and Public access prevention enforced. An external auditor needs read-only access to a single CSV object for the next 7 days. The company does not want to create or manage an IAM identity for the auditor, and the bucket's security settings must remain unchanged. Which approach should you take?

  • Add the allUsers principal to the bucket IAM policy with the Storage Object Viewer role, then remove the binding after 7 days.

  • Generate a Cloud Storage V4 signed URL for the CSV object that expires in 7 days using a service account that has storage.objects.get permission, and send the URL to the auditor.

  • Temporarily disable Uniform bucket-level access, add an object-level READ ACL for the auditor's email address, and re-enable Uniform bucket-level access after 7 days.

  • Change the bucket's Public access prevention setting to "inherited" and rely on the obscurity of the object's name for security.

GCP Associate Cloud Engineer
Ensuring successful operation of a cloud solution
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot