GCP Associate Cloud Engineer Practice Question

Your security team wants to replace instance-level SSH keys with an IAM-based mechanism on all new Compute Engine VMs. Linux administrators must still be able to run sudo after logging in. You need to implement this with the fewest possible steps before the next VM is created. What should you do?

  • Create a startup script that writes each administrator's public key to /home/$/.ssh/authorized_keys on every VM.

  • Enable IAP for TCP forwarding on the project and grant the administrators group roles/iap.tunnelResourceAccessor.

  • Add the metadata key enable-oslogin=TRUE at the project level and grant the administrators group the IAM role roles/compute.osAdminLogin.

  • Add the metadata key block-project-ssh-keys=TRUE at the project level and grant the administrators group roles/compute.instanceAdmin.v1.

GCP Associate Cloud Engineer
Planning and implementing a cloud solution
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot