🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 26 minutes remaining!

GCP Associate Cloud Engineer Practice Question

Your CI pipeline runs as the user-managed service account [email protected] in Project A. It needs to deploy a new revision to Cloud Run in Project B by impersonating the existing service account [email protected]. Security policy prohibits creating or storing long-lived service account keys. Which single IAM binding provides the least privilege required for the pipeline to obtain short-lived credentials and act as deploy-sa?

  • Generate a JSON key for deploy-sa and store it securely in Secret Manager for the pipeline to use.

  • Grant build-sa the role Service Account User (roles/iam.serviceAccountUser) on deploy-sa.

  • Grant build-sa the basic Owner role on Project B.

  • Grant build-sa the role Service Account Token Creator (roles/iam.serviceAccountTokenCreator) on deploy-sa.

GCP Associate Cloud Engineer
Configuring access and security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot