Skip to content

Configuring access and security Questions

Practice questions for Configuring access and security topic in Google Cloud Associate Cloud Engineer. 46 questions covering this domain.

46 questions12 easy22 medium12 hard
Q1
hard

An operator must create a VM that runs as a service account and later impersonate that same service account from a laptop by using gcloud. Which permi...

Q2
hard

A GKE workload must authenticate as a Google Cloud service account from inside the cluster without using long-lived keys. Which role is designed for t...

Q3
easy

Which role lets a principal attach a service account to a resource, but does not let the principal use --impersonate-service-account?

Q4
easy

Which role allows a principal to create short-lived credentials for a service account and use the gcloud --impersonate-service-account flag?

Q5
medium

A service needs only short-lived OIDC ID tokens for a service account and no access tokens or signing permissions. Which role should be granted?

Q6
medium

An analyst needs to read objects and list bucket contents, but must not modify data. Which Cloud Storage role is the best fit?

Q7
medium

A new custom VPC network has no explicit firewall rules. What is the default behavior?

Q8
medium

A security team wants firewall rules to follow VM identity and be harder for instance admins to alter casually by editing metadata. Which targeting me...

Q9
easy

Which IAM role type should generally not be used in production because it is highly permissive?

Q10
medium

A contractor must upload objects to a bucket but must not be able to view, delete, or overwrite existing objects. Which role is the best fit?

Q11
hard

A regulated team needs every administrative API call against a project to be reviewed in a tamper-evident, retained log even if a project owner tries ...

Q12
easy

Which Google Cloud service securely stores and manages secrets such as API keys and passwords?

Q13
medium

A developer must allow a Cloud Run service to read messages from a Pub/Sub subscription. Which IAM grant is the most appropriate?

Q14
easy

Which IAM concept binds a principal to a role on a specific resource?

Q15
medium

An IAM policy must reflect that a single role applies to many users at once with simplified administration when employees join or leave. Which approac...

Q16
medium

A developer must call a Google Cloud API from code running on a Compute Engine VM without managing key files. Which authentication mechanism should be...

Q17
medium

An administrator must periodically rotate a customer-managed Cloud KMS key that protects data in Cloud Storage. Which capability supports this require...

Q18
medium

An administrator must allow a developer to view objects in a single Cloud Storage bucket but not other buckets in the project. What is the most direct...

Q19
easy

Which type of IAM principal represents a non-human service identity used by applications running on Google Cloud?

Q20
hard

An organization must ensure that Cloud Storage data cannot be exfiltrated by service accounts whose credentials are stolen and used from outside the o...

Sign in to see all 46 questions

Create a free account to browse all questions — completely free during our launch phase.