🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 53 minutes remaining!

GCP Professional Cloud Security Engineer Practice Question

Your security team discovered that several Cloud Storage objects are publicly readable because developers added object-level ACLs directly on those objects. They want to eliminate this risk across all production buckets while simplifying future permission audits. You must implement a solution that:

  • Prevents any new or existing object ACLs from granting access.
  • Allows you to manage access only through IAM roles granted on the bucket.
  • Keeps data available to current internal workloads that already have Storage Object Viewer on the bucket.
    Which action will meet these requirements with the least operational overhead?
  • Enable uniform bucket-level access on the affected buckets and rely solely on IAM policies for future permissions.

  • Move the objects into new buckets where Public Access Prevention is enforced, and manage per-object sharing there.

  • Remove all existing object ACLs with the gsutil acl ch -d AllUsers command and instruct developers to avoid setting ACLs going forward.

  • Create an IAM deny policy that blocks the storage.objects.create permission when it includes an ACL granting AllUsers access.

GCP Professional Cloud Security Engineer
Configuring Access
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot