🔥 40% Off Crucial Exams Memberships — Deal ends today!

28 minutes, 55 seconds remaining!

GCP Associate Cloud Engineer Practice Question

Your team runs a Compute Engine VM that processes orders. The VM's user-managed service account must 1) pull messages from the orders-sub Pub/Sub subscription and 2) upload the resulting PDF receipt files only to the gs://processed-orders bucket. Which IAM configuration best follows the principle of least privilege?

  • Grant the predefined Editor role on the project to the service account.

  • Grant roles/pubsub.subscriber on the orders-sub subscription and roles/storage.objectCreator on the gs://processed-orders bucket to the service account.

  • Create a custom role with only the required Pub/Sub and Cloud Storage permissions and grant it to the service account at the organization level.

  • Grant roles/pubsub.admin and roles/storage.admin on the project to the service account.

GCP Associate Cloud Engineer
Configuring access and security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot