🔥 40% Off Crucial Exams Memberships — Deal ends today!

8 minutes, 57 seconds remaining!

GCP Professional Cloud Security Engineer Practice Question

A Cloud Storage bucket that stores quarterly financial statements currently has uniform bucket-level access enabled. During an audit, you need to grant read access on a single object (gs://fin-statements/Q1-2025.pdf) to one external accountant who uses a Gmail address. The accountant must not see any other objects in the bucket. What must you do before you can add an object-level ACL that meets this requirement?

  • Grant the accountant the roles/storage.objectViewer role on the bucket and rely on object retention policies to protect other files.

  • Enable Public Access Prevention and then assign a READER ACL to the object.

  • Disable uniform bucket-level access on the bucket, then apply an ACL that grants READER permission on the object to the accountant's Gmail address.

  • Add an IAM condition on the bucket binding that restricts roles/storage.objectViewer to the specific object path.

GCP Professional Cloud Security Engineer
Ensuring data protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot