GCP Associate Cloud Engineer Practice Question

Your company has a Google Cloud organization with separate "Prod" and "Dev" folders that each contain dozens of projects. Security requires that no Cloud Storage bucket in production can ever be made publicly accessible, while developers may still create public buckets in the Dev folder for testing. As the Associate Cloud Engineer, which approach best meets these requirements with the least operational overhead and without affecting the Dev folder?

  • Manually enable Uniform bucket-level access and remove public IAM principals on every existing and new bucket in Prod projects.

  • Create a VPC Service Controls perimeter around all Prod projects to block public access to Cloud Storage.

  • At the Organization level, add an IAM deny policy that blocks the roles/storage.objectViewer role for the principals allUsers and allAuthenticatedUsers.

  • Attach the constraints/storage.publicAccessPrevention organization policy to the Prod folder and set it to enforced, leaving the Dev folder without the policy.

GCP Associate Cloud Engineer
Setting up a cloud solution environment
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot