🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 51 minutes remaining!

GCP Associate Cloud Engineer Practice Question

Your company runs more than 500 Compute Engine VMs that were created from current Google-provided Linux and Windows images and all use the project's default Compute Engine service account. The security team wants to start using VM Manager so they can view package inventory and vulnerability findings for every VM in the Cloud console without having to install any additional software. What single action will allow the VMs to begin reporting this data as soon as possible while following the principle of least privilege?

  • Create a new custom service account that has the Cloud Platform role, attach it to every VM, and perform a rolling reboot.

  • Add the metadata key enable-osconfig=true at the project level; no API or IAM changes are necessary.

  • Grant the project's default Compute Engine service account the roles/editor role and then restart all VMs so the agent can refresh its credentials.

  • Enable the OS Config API (osconfig.googleapis.com) in the project; this creates the OS Config service agent with the roles/osconfig.serviceAgent role so the pre-installed agent can upload inventory and vulnerability data.

GCP Associate Cloud Engineer
Planning and implementing a cloud solution
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot