🔥 40% Off Crucial Exams Memberships — Deal ends today!

12 minutes, 16 seconds remaining!

GCP Associate Cloud Engineer Practice Question

Your organization operates about 200 Compute Engine VMs across several projects. Developers currently access the VMs over SSH using individual public keys stored in instance metadata. Security wants to ensure that:

  • SSH access can be revoked immediately when a user's Cloud Identity account is disabled.
  • Administrators can see which Google account opened every SSH session in Cloud Logging.

Which approach meets these requirements with the least operational effort?

  • Convert the VMs into managed instance groups and deploy an endpoint security agent that records and reports SSH login activity.

  • Enable OS Login at the project level for all VMs, delete existing SSH keys from metadata, and grant developers the compute.osLogin IAM role.

  • Add a startup script that rotates instance-level SSH keys daily and stores the new keys in Secret Manager, granting developers access to the secrets.

  • Require Identity-Aware Proxy (IAP) TCP forwarding by adding a firewall rule that blocks direct TCP 22 and instruct users to connect through IAP.

GCP Associate Cloud Engineer
Planning and implementing a cloud solution
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot