GCP Professional Cloud Security Engineer Practice Question
Your security team is enforcing least-privilege access for AI workloads. A group of external analysts must perform online predictions by invoking an existing Vertex AI endpoint, but they must never be able to list or download the training data that resides in a Cloud Storage bucket. Which IAM assignment best satisfies the requirement while following the principle of least privilege?
Grant the analysts the Vertex AI User role (roles/aiplatform.user) only on the target endpoint and grant no Cloud Storage roles.
Grant the analysts the Vertex AI Viewer role on the project and the Storage Object Viewer role on the training-data bucket.
Grant the analysts the Vertex AI Developer role on the project; do not assign any Cloud Storage permissions.
Grant the analysts the Vertex AI Admin role on the project and Storage Object Viewer on the bucket, then rely on audit logs to detect misuse.
Granting the analysts the Vertex AI User role only on the specific endpoint lets them call projects.locations.endpoints.predict without permitting them to create, modify, or view other Vertex AI resources. Because the role contains no Cloud Storage permissions, analysts cannot read objects in the bucket that contains the training data. All storage access remains limited to the service account that Vertex AI uses at prediction time. Assigning any Storage role or broader Vertex AI role (Developer or Admin) would violate least-privilege by exposing data or administrative capabilities the analysts do not need.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the Vertex AI User role (roles/aiplatform.user) used for?
Open an interactive chat with Bash
How does least-privilege access improve security?
Open an interactive chat with Bash
How is data in the Cloud Storage bucket accessed during predictions without permissions for analysts?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Ensuring data protection
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .