🔥 40% Off Crucial Exams Memberships — Deal ends today!

3 hours, 1 minute remaining!

GCP Professional Cloud Architect Practice Question

Your company uses a customer-managed symmetric encryption key stored in Cloud KMS to protect objects in a production Cloud Storage bucket. A Compute Engine service account must upload and download objects that the bucket automatically encrypts with this key. Compliance mandates that only the central Security team can rotate, disable, or otherwise administer the key. Which single IAM role should you grant to the service account on the specific CryptoKey to satisfy these requirements?

  • Grant roles/cloudkms.cryptoKeyEncrypterDecrypter on the CryptoKey.

  • Grant roles/owner on the project that contains the key ring.

  • Grant roles/storage.objectAdmin on the Cloud Storage bucket.

  • Grant roles/cloudkms.admin on the CryptoKey.

GCP Professional Cloud Architect
Designing for security and compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot