🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 27 minutes remaining!

GCP Associate Cloud Engineer Practice Question

Your company requires that every SSH session to Compute Engine VMs be authorized through IAM and that sudo access be granted only when explicitly approved. A developer needs temporary root-shell access to a single VM for the next seven days to apply a hot-fix. Which approach best meets the security team's requirements while minimizing manual effort?

  • Add the developer's public SSH key to the instance metadata and delete the key after seven days.

  • Enable OS Login on the VM and add an IAM conditional binding that grants the developer the roles/compute.osAdminLogin role on that instance, expiring after seven days.

  • Enable IAP TCP forwarding for the VM and open TCP port 22 to the IAP proxy IP range; no additional IAM roles are required.

  • Grant the developer the roles/compute.instanceAdmin.v1 role at the project level so they can reset the root password through the console.

GCP Associate Cloud Engineer
Planning and implementing a cloud solution
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot