🔥 40% Off Crucial Exams Memberships — Deal ends today!

2 hours, 27 minutes remaining!

GCP Associate Cloud Engineer Practice Question

You created a user-managed service account that has the Storage Object Viewer role. An existing Compute Engine VM currently runs using the default Compute Engine service account, but the application on the VM now needs to access objects in a private Cloud Storage bucket by assuming the new identity. You want to make this change with the least possible downtime and without replacing the VM. What should you do?

  • Add a metadata entry named service-account-email with the new service account on the running VM; no restart is required.

  • Grant the Storage Object Viewer role to the new service account; the VM will automatically use it on its next token refresh.

  • Generate an access token for the new service account and store it as an environment variable for the application on the VM.

  • Stop the VM, run gcloud compute instances set-service-account with the new service account, then start the VM.

GCP Associate Cloud Engineer
Configuring access and security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot