
Google CloudAssociate Cloud Engineer
Domain 4Objective 2
4.2 Managing Service Accounts ASSOCIATE-CLOUD-ENGINEER Practice Questions (Page 3)
Part of the Configuring access and security domain, which accounts for ~20% of the ASSOCIATE-CLOUD-ENGINEER exam.
21questions here
5free pages
8concepts
~20%of the exam
Questions 11–15
- 11
You need to generate a short-lived OAuth2 access token for a service account to authenticate to a Google Cloud API. What is the default maximum lifetime of such an access token?
Select an answer first - 12
What is the purpose of service account impersonation?
Select an answer first - 13
A GKE cluster runs multiple microservices. One microservice needs to publish messages to Pub/Sub, and another needs to read from a specific Cloud Storage bucket. The team wants to grant each microservice only the permissions it needs. What is the best approach?
Select an answer first - 14
A company runs workloads on AWS and wants them to access Google Cloud Storage. They want to avoid creating and rotating service account keys. What should they configure?
Select an answer first - 15
You need to grant a service account permission to publish messages to a Pub/Sub topic. Which IAM role should you assign to the service account?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Google Cloud. “ASSOCIATE-CLOUD-ENGINEER” is a trademark of its owner, used for identification only.