GCP Professional Cloud Architect Practice Question

Treasure Maps Inc. operates 20 Google Cloud projects in a single organization. Roughly 50 data scientists rotate among these projects every quarter and must always have the BigQuery Data Viewer role wherever they are currently assigned. The IAM team wants to

  • avoid updating dozens of individual role bindings each time people move,
  • inherit team membership from an existing Azure AD security group named ds-team, and
  • add several internal CI/CD service accounts so they receive the same access.

Which identity construct should receive the BigQuery Data Viewer role on each project to satisfy all requirements with the least operational effort?

  • Individual external identities for each data scientist via Workforce Identity Federation, each granted the BigQuery Data Viewer role directly

  • A custom IAM role assigned separately to every project and bound to principals as needed

  • A Google Group that is synchronized with the Azure AD ds-team group, with the CI/CD service accounts added as additional members

  • Each data scientist's personal Google Account, granted the BigQuery Data Viewer role directly in every project

GCP Professional Cloud Architect
Designing for security and compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot