🔥 40% Off Crucial Exams Memberships — Deal ends today!

4 minutes, 39 seconds remaining!

GCP Professional Cloud Architect Practice Question

A company runs a Compute Engine VM under the service account [email protected]. The VM must (1) pull messages from a single Pub/Sub subscription called orders-sub and (2) write processed results as objects into the Cloud Storage bucket gs://order-results, both in the inventory-prod project. Today the service account has roles/pubsub.subscriber and roles/storage.admin on the entire inventory-prod project. The security team wants to apply the principle of least privilege without disrupting the workload. What should you do?

  • Move the subscription and bucket to a separate project and grant the service account the Editor role on that new project.

  • Keep the current project-level roles but add an IAM condition to each so they apply only during business hours.

  • Replace the two existing roles with a single custom role that includes pubsub.subscriptions.consume and storage.objects.* permissions, and grant the custom role on the entire project.

  • Remove the project-level bindings and grant the service account the Pub/Sub Subscriber role on the orders-sub subscription and the Storage Object Creator role on the gs://order-results bucket.

GCP Professional Cloud Architect
Designing for security and compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot