GCP Professional Cloud Architect Practice Question
You are designing IAM for a new analytics platform on Google Cloud. It runs a Cloud Run service that queries BigQuery. Requirements: 1) The service must authenticate to BigQuery without relying on developer credentials and should benefit from automatic key rotation. 2) A team of analysts whose membership changes frequently needs Viewer access to Cloud Logging logs. 3) The security team wants to apply IAM constraints to every employee account in one action. Which identity types satisfy requirements 1, 2, and 3 respectively?
Cloud Identity or Google Workspace domain; Service Account; individual Google Accounts
Google Account; Google Group; Service Account
Service Account; Google Group; Cloud Identity or Google Workspace domain
Service Account; individual Google Accounts; Google Group
A service account is the recommended identity for workloads such as Cloud Run services because it is not tied to a human user and its keys are automatically rotated by Google when you avoid long-lived user-managed keys. A Google Group is ideal for the analysts: IAM roles can be granted to the group once, and changes in membership are handled in the group, not in every policy. To cover every employee with a single IAM binding, you grant the role to the organization's Cloud Identity or Google Workspace domain principal (domain:example.com), which represents all accounts in that domain. The other options mis-apply identity types: individual Google Accounts should not be embedded in code; service accounts are not meant to group humans; and Google Groups do not automatically include all domain users.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a service account in Google Cloud?
Open an interactive chat with Bash
How does a Google Group help in managing IAM roles?
Open an interactive chat with Bash
What is a Google Workspace or Cloud Identity domain principal?
Open an interactive chat with Bash
What is a service account, and how does it satisfy requirement 1?
Open an interactive chat with Bash
Why is a Google Group a good fit for providing Viewer access, and how does it fulfill requirement 2?
Open an interactive chat with Bash
How does Cloud Identity or Google Workspace domain satisfy requirement 3 for applying IAM constraints?
Open an interactive chat with Bash
GCP Professional Cloud Architect
Designing for security and compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .