GCP Professional Cloud Architect Practice Question
A global retail company wants to let hundreds of development teams deploy only pre-approved Google Cloud configurations-such as a standard 3-tier GKE application stack and a BigQuery dataset with predefined IAM policies-without giving them owner rights on the organization's projects. Security architects also need a single place to update base images and enforce labels across all deployments. Which approach best meets these requirements?
Create products in Google Cloud Service Catalog backed by Terraform configurations for each approved stack, grant teams the Service Catalog Consumer role, and let architects manage template versions.
List the required solutions on Google Cloud Marketplace private offers and instruct teams to subscribe; security architects update images through Marketplace vendor updates.
Store standard Terraform modules in Cloud Source Repositories and rely on a policy that only permits terraform apply from those repos while architects update the modules.
Publish container images and deployment YAML files to Artifact Registry and Cloud Storage, then give teams Storage Object Viewer access to deploy them with kubectl apply commands.
Google Cloud Service Catalog lets central administrators publish vetted Terraform or Deployment Manager configurations as catalog entries. Developer teams with limited IAM roles (for example, servicecatalog.consumer) can self-provision those entries without needing broader project-level permissions. When architects update a catalog entry-such as changing a base container image or adding mandatory labels-the changes propagate to future deployments, ensuring ongoing governance. Merely using Cloud Marketplace, manual Terraform modules in Git, or OS Config policies does not provide the same controlled self-service catalog with versioned, centrally managed templates and delegated consumer access.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Google Cloud Service Catalog?
Open an interactive chat with Bash
What role does Terraform play in Google Cloud Service Catalog?
Open an interactive chat with Bash
How does Service Catalog Consumer role limit permissions?
Open an interactive chat with Bash
What is Google Cloud Service Catalog?
Open an interactive chat with Bash
How does the Service Catalog Consumer role work?
Open an interactive chat with Bash
Why are Terraform configurations suitable for Service Catalog entries?
Open an interactive chat with Bash
GCP Professional Cloud Architect
Analyzing and optimizing technical and business processes
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .