🔥 40% Off Crucial Exams Memberships — Deal ends today!

3 hours, 1 minute remaining!

GCP Professional Cloud Architect Practice Question

ExampleSoft must give an external penetration tester, Alice, temporary read-only access to Cloud Logging data in the production project. She is outside your Google Workspace, and you are not permitted to create service accounts or export logs. Which identity type should receive the Logs Viewer role (roles/logging.viewer) to uphold least-privilege principles and maintain good credential hygiene?

  • Add Alice to a new Google Group in ExampleSoft's domain and assign the role to that group.

  • Create a dedicated service account, generate a JSON key, and give the key file to Alice.

  • Grant the role to Alice's personal Google Account (for example, [email protected]).

  • Configure workload identity federation so Alice receives temporary credentials mapped to an external principal.

GCP Professional Cloud Architect
Designing for security and compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot