🔥 40% Off Crucial Exams Memberships — Deal ends today!

3 hours, 1 minute remaining!

GCP Associate Cloud Engineer Practice Question

Your security team has prohibited granting the storage.objects.getIamPolicy permission in the payroll project. A group of analysts must be able to upload new objects and delete outdated objects in a sensitive Cloud Storage bucket, but they must not view or change IAM policies. The available predefined Storage roles all include the forbidden permission. How should you grant the required access while respecting the security constraint?

  • Use object ACLs to give the analysts OWNER access on all objects in the bucket while leaving IAM unchanged.

  • Create an organization- or project-level custom IAM role that includes only storage.objects.create and storage.objects.delete, then grant that role on the bucket to the analysts' Google Group.

  • Grant the analysts the predefined Storage Object Admin role on the bucket and add an IAM deny policy for storage.objects.getIamPolicy.

  • Enable Uniform bucket-level access and grant the analysts the Storage Admin role on the bucket so they inherit all necessary permissions automatically.

GCP Associate Cloud Engineer
Setting up a cloud solution environment
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot