GCP Associate Cloud Engineer Practice Question

A support engineer occasionally needs to investigate errors by examining application log entries in Cloud Logging for a single project. They must not be able to list Cloud Storage objects, start or stop VMs, or view audit logs. Which single IAM role should you grant to satisfy the requirement with the principle of least privilege?

  • Grant the basic Viewer role (roles/viewer) at the project level.

  • Grant the Logs Viewer predefined role (roles/logging.viewer) at the project level.

  • Grant the Logs Private Viewer role (roles/logging.privateLogViewer) at the project level.

  • Grant the Monitoring Viewer role (roles/monitoring.viewer) at the project level.

GCP Associate Cloud Engineer
Configuring access and security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot