GCP Associate Cloud Engineer Practice Question

Your security team wants to let the on-call operators restart production Compute Engine VMs during incidents, but not create, delete, or modify any other resource. You inspected predefined roles such as Compute Instance Admin (v1) and found they grant many permissions beyond starting and stopping instances. What is the most appropriate IAM approach to meet the requirement while following least-privilege guidelines?

  • Grant the operators group the predefined Editor role on the project and rely on audit logs for oversight.

  • Grant the operators group the predefined Compute Instance Admin (v1) role on the project.

  • Enable OS Login and grant the operators group roles/iam.serviceAccountUser on the default Compute Engine service account.

  • Create a custom role containing only compute.instances.start and compute.instances.stop permissions, then bind it to the operators group.

GCP Associate Cloud Engineer
Configuring access and security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot