
Google CloudAssociate Cloud Engineer
Domain 4Objective 1
4.1 Managing IAM ASSOCIATE-CLOUD-ENGINEER Practice Questions (Page 1)
Part of the Configuring access and security domain, which accounts for ~20% of the ASSOCIATE-CLOUD-ENGINEER exam.
17questions here
4free pages
8concepts
~20%of the exam
Questions 1–5
- 1
Which of the following is a valid member type that can be attached to an IAM role?
Select an answer first - 2
Your company has a policy that only a specific group of DevOps engineers should be able to create and manage Cloud Storage buckets, but they should NOT be able to delete buckets or change IAM policies on them. The predefined 'Storage Admin' role is too broad because it allows bucket deletion and IAM management. What should you do?
Select an answer first - 3
Which IAM role type is most appropriate when you need to grant a user the ability to view but not modify a specific set of Compute Engine resources, and you want to avoid granting broad permissions across all services?
Select an answer first - 4
A user is a member of a Google Group that has been granted 'roles/storage.objectViewer' at the project level. What access does the user have to objects in a Cloud Storage bucket in that project?
Select an answer first - 5
Which of the following correctly describes the order of IAM policy inheritance in the Google Cloud resource hierarchy?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Google Cloud. “ASSOCIATE-CLOUD-ENGINEER” is a trademark of its owner, used for identification only.