🔥 40% Off Crucial Exams Memberships — Deal ends today!

12 minutes, 0 second remaining!

GCP Professional Cloud Security Engineer Practice Question

A financial-services company stores incoming transaction files in a regional Cloud Storage bucket (us-central1) located in project B. The bucket is configured to use a customer-managed encryption key (CMEK) that resides in project C in the same region. Files are written to the bucket by a data-ingestion service account that already has the Storage Object Creator role on the bucket. During testing, every upload fails with the error "PERMISSION_DENIED: 400 Bad Request - could not encrypt; permission denied on Cloud KMS key." Which action will resolve the error while adhering to the principle of least privilege?

  • Grant the Storage Object Creator role on the bucket to the Cloud KMS service agent for project C (service-<PROJECT_C_NUMBER>@gcp-sa-cloudkms.iam.gserviceaccount.com).

  • Grant the Storage Admin role on the bucket to the data-ingestion service account.

  • Grant the Cloud KMS CryptoKey Encrypter/Decrypter role on the CMEK key to the Cloud Storage service agent for project B (service-<PROJECT_B_NUMBER>@gs-project-accounts.iam.gserviceaccount.com).

  • Grant the Cloud KMS Admin role on project C to the Cloud Storage service agent for project B.

GCP Professional Cloud Security Engineer
Ensuring data protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot