GCP Associate Cloud Engineer Practice Question

Your team created a user-managed service account named [email protected]. The account must read objects from every Cloud Storage bucket in project log-proj. You want to grant the predefined Storage Object Viewer role to the service account at the project level without modifying any other existing IAM bindings. Which gcloud command accomplishes this goal?

  • gcloud projects set-iam-policy log-proj policy.yaml (with the new binding added manually to the file)

  • gcloud storage buckets add-iam-policy-binding gs://log-proj --member=serviceAccount:[email protected] --role=roles/storage.objectViewer

  • gcloud projects add-iam-policy-binding log-proj --member=serviceAccount:[email protected] --role=roles/storage.objectViewer

  • gcloud iam service-accounts add-iam-policy-binding [email protected] --member=project:log-proj --role=roles/storage.objectViewer

GCP Associate Cloud Engineer
Configuring access and security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot