🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 53 minutes remaining!

GCP Associate Cloud Engineer Practice Question

Your organization's infosec team currently has the IAM role Security Reviewer (roles/iam.securityReviewer) on every project. A new compliance requirement states that these auditors must also be able to disable and delete service account keys, but they must not be able to create keys or modify the service accounts themselves. No single Google-managed (predefined) role exactly matches these needs. What should you do to satisfy the requirement while following the principle of least privilege?

  • Attach the Service Account Token Creator role (roles/iam.serviceAccountTokenCreator) to the auditors; it allows them to act on behalf of service accounts and therefore manage keys.

  • Create a project-level custom role that includes only iam.serviceAccountKeys.disable and iam.serviceAccountKeys.delete, then grant that role to the infosec group in addition to their existing Security Reviewer role.

  • Grant the infosec group the Service Account Admin role (roles/iam.serviceAccountAdmin) because it already contains all service-account-related permissions.

  • Add the predefined Service Account Key Admin role (roles/iam.serviceAccountKeyAdmin) to the infosec group, since it is the least-privilege way to manage keys.

GCP Associate Cloud Engineer
Configuring access and security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot