GCP Associate Cloud Engineer Practice Question

Your security team created a user-managed service account named [email protected] that already has permission to read sensitive BigQuery datasets. Data analysts need to run bq queries from Cloud Shell by impersonating this service account and obtaining short-lived OAuth2 tokens. Analysts must not be able to create or download key files for the account. Following least-privilege, which IAM role should you grant to the analyst group on reports-sa?

  • Grant roles/bigquery.dataViewer at the project level

  • Grant roles/iam.serviceAccountTokenCreator on reports-sa

  • Grant roles/iam.serviceAccountKeyAdmin on reports-sa

  • Grant roles/iam.serviceAccountUser on reports-sa

GCP Associate Cloud Engineer
Configuring access and security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot