GCP Associate Cloud Engineer Practice Question

A production project contains the service account [email protected]. Your organization forbids the distribution of long-lived service-account key files. A data engineer needs to execute gcloud commands from her workstation as this service account to launch BigQuery jobs, and she must not receive any broader permissions in the project than are strictly required for impersonation. Which single IAM policy binding will meet these requirements?

  • Grant the data engineer the Service Account User role (roles/iam.serviceAccountUser) on the bq-runner@analytics-prod service account.

  • Grant the data engineer the Service Account Token Creator role (roles/iam.serviceAccountTokenCreator) at the project level.

  • Grant the data engineer the Service Account Token Creator role (roles/iam.serviceAccountTokenCreator) on the bq-runner@analytics-prod service account.

  • Grant the data engineer the Editor role (roles/editor) at the project level.

GCP Associate Cloud Engineer
Configuring access and security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot