🔥 40% Off Crucial Exams Memberships — Deal ends today!

2 hours, 31 minutes remaining!

GCP Associate Cloud Engineer Practice Question

Your company is deploying a custom analytics application on a Compute Engine virtual machine. The software must read objects from a private Cloud Storage bucket and write usage metrics to Cloud Monitoring. Interactive logins on the VM are disabled, so the application must authenticate to Google Cloud APIs without any end-user credentials. Which identity should you configure so the application can obtain short-lived access tokens automatically while following Google-recommended practices for workloads?

  • Add the VM to a Google Group that has the Storage Object Viewer and Monitoring Metric Writer roles.

  • Create a user-managed service account, grant it the required IAM roles, and attach it to the VM instance.

  • Assign the project's Owner basic role to the VM through custom instance metadata key-value pairs.

  • Generate an OAuth 2.0 client ID and secret, then store them in the VM so the application can request refresh tokens.

GCP Associate Cloud Engineer
Configuring access and security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot