
Google CloudAssociate Cloud Engineer
Domain 4Objective 2
4.2 Managing Service Accounts ASSOCIATE-CLOUD-ENGINEER Practice Questions (Page 1)
Part of the Configuring access and security domain, which accounts for ~20% of the ASSOCIATE-CLOUD-ENGINEER exam.
21questions here
5free pages
8concepts
~20%of the exam
Questions 1–5
- 1
Which of the following is a Google-managed service account that is automatically created and used by Google Cloud services?
Select an answer first - 2
What is the primary use case for a short-lived ID token issued to a service account?
Select an answer first - 3
A CI/CD pipeline needs to authenticate to Google Cloud APIs for a deployment step. The pipeline runs on a third-party CI service and cannot use a service account key stored in the repository. The team wants to use short-lived credentials. What is the recommended approach?
Select an answer first - 4
You want to allow a user to temporarily act as a service account to generate an access token for a one-time task. Which IAM role should you grant the user on the service account?
Select an answer first - 5
What is the primary benefit of using Workload Identity in GKE compared to using service account keys?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Google Cloud. “ASSOCIATE-CLOUD-ENGINEER” is a trademark of its owner, used for identification only.