GCP Associate Cloud Engineer Practice Question

Your startup runs a batch job on a Compute Engine VM whose attached service account is [email protected]. The job must read (but not write) objects from a single Cloud Storage bucket named audit-logs that lives in the same project. To follow the principle of least privilege and avoid granting broader access, which IAM assignment should you create?

  • Grant the Viewer basic role to the service account at the organization level.

  • Grant the Storage Object Viewer role to the service account on the project.

  • Grant the Storage Object Viewer role to [email protected] on the audit-logs bucket.

  • Grant the Storage Admin role to the service account on the audit-logs bucket.

GCP Associate Cloud Engineer
Configuring access and security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot