🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 0 minute remaining!

GCP Associate Cloud Engineer Practice Question

Your company's compliance auditor has been added to a Google Cloud project. The auditor must be able to read all Cloud Logging entries across every service in the project but must not view objects in Cloud Storage, query BigQuery tables, or modify any resources. Which IAM role should you grant to the auditor to meet these requirements while following the principle of least privilege?

  • Grant the basic Viewer role (roles/viewer) at the project level.

  • Create a custom role containing only logging read permissions and grant it at the project level.

  • Grant the predefined Logging Viewer role (roles/logging.viewer) at the project level.

  • Grant the predefined Logging Admin role (roles/logging.admin) at the project level.

GCP Associate Cloud Engineer
Configuring access and security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot