GCP Associate Cloud Engineer Practice Question

Your project contains a user-managed service account named analytics-sa that already has the Storage Object Viewer role on a Cloud Storage bucket where job outputs are written. A data analyst, [email protected], tries to launch a Dataflow job configured to run as analytics-sa but immediately receives the error: "principal is not authorized to actAs the requested service account." You must resolve the issue while following least-privilege practices. Which IAM change should you make?

  • Grant [email protected] the Storage Object Viewer (roles/storage.objectViewer) role on analytics-sa.

  • Grant analytics-sa the Service Account Token Creator (roles/iam.serviceAccountTokenCreator) role on the project.

  • Grant analytics-sa the Editor (roles/editor) role on the project.

  • Grant [email protected] the Service Account User (roles/iam.serviceAccountUser) role on analytics-sa.

GCP Associate Cloud Engineer
Configuring access and security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot