GCP Professional Cloud Architect Practice Question
Your organization BigRetail has a Cloud Identity domain called bigretail.com. You must update IAM so that: every current and future employee automatically receives the Billing Account Viewer role on the company's central billing account without any manual user or group maintenance, and Cloud Build pipelines can deploy containers to multiple GKE projects without distributing long-lived user credentials. Which combination of principal types best satisfies these two requirements?
Create an All-Employees Google Group for Billing Account Viewer; create a dedicated Google Account for the pipeline to deploy clusters.
Grant Billing Account Viewer to the bigretail.com domain; grant the Cloud Build default service account the necessary GKE deployment roles.
Individually assign each employee's Google Account the Billing Account Viewer role; add the pipeline to a Google Group that has the deployment roles.
Create an organization-wide service account for Billing Account Viewer; grant the bigretail.com domain the deployment roles needed by Cloud Build.
Granting a role to the Cloud Identity (or Google Workspace) domain meets the first requirement because a domain principal (domain:bigretail.com) automatically includes all existing and future user accounts in that domain, eliminating the need to manage group membership. For the CI/CD pipelines, Cloud Build already runs with its own Google-managed service account ([email protected]). Granting the required GKE deployment roles to that service account allows builds to obtain short-lived OAuth tokens at runtime and avoids sharing persistent user credentials. The alternative options either require ongoing manual administration, rely on individual user accounts, or misuse identity types (for example, using a domain principal for automation tasks).
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Cloud Identity domain in GCP?
Open an interactive chat with Bash
How does a Cloud Build service account function in GCP?
Open an interactive chat with Bash
What is the difference between a domain principal and a service account?
Open an interactive chat with Bash
What is a domain principal in GCP IAM?
Open an interactive chat with Bash
How does the Cloud Build default service account work?
Open an interactive chat with Bash
Why is granting roles to groups or individual accounts less ideal for scalability?
Open an interactive chat with Bash
GCP Professional Cloud Architect
Designing for security and compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .