🔥 40% Off Crucial Exams Memberships — Deal ends today!

5 minutes, 25 seconds remaining!

GCP Associate Cloud Engineer Practice Question

Your team runs a GKE cluster with Workload Identity enabled. A pod in namespace "payments" needs to list objects in a Cloud Storage bucket. You created a Google service account [email protected] and granted it the Storage Object Viewer role on the bucket. Which additional configuration will let the pod authenticate without service account keys?

  • Add the Google service account as an imagePullSecret and rely on Application Default Credentials inside the container to pick up the secret.

  • Grant the Storage Object Viewer role directly to member serviceAccount:PROJECT_ID.svc.id.goog[payments/gcs-reader-ksa] on the bucket and mount a JSON key file for gcs-reader into the pod.

  • Bind roles/iam.workloadIdentityUser on [email protected] to member serviceAccount:PROJECT_ID.svc.id.goog[payments/gcs-reader-ksa], then annotate the Kubernetes service account gcs-reader-ksa in the payments namespace with the GSA email.

  • Give the Kubernetes service account the roles/iam.serviceAccountUser role at the project level and set the pod spec serviceAccountName field to the Google service account email.

GCP Associate Cloud Engineer
Configuring access and security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot