
Google CloudAssociate Cloud Engineer
Domain 4Objective 2
4.2 Managing Service Accounts ASSOCIATE-CLOUD-ENGINEER Practice Questions (Page 4)
Part of the Configuring access and security domain, which accounts for ~20% of the ASSOCIATE-CLOUD-ENGINEER exam.
21questions here
5free pages
8concepts
~20%of the exam
Questions 16–20
- 16
A team runs a containerized application in Google Kubernetes Engine (GKE). The application needs to read from a Cloud Storage bucket. The team wants to avoid using static service account keys and follow least privilege. What should they configure?
Select an answer first - 17
You are assigning IAM roles to a service account for an application that only needs to read objects from a specific Cloud Storage bucket. Which role should you grant to follow the principle of least privilege?
Select an answer first - 18
What is the purpose of a workload identity pool in Workload Identity Federation?
Select an answer first - 19
You are deploying a Cloud Function that needs to access a Cloud Storage bucket. You want to attach a service account to the function. Which of the following is true about attaching a service account to a Cloud Function?
Select an answer first - 20
A service account used by a batch job was previously granted the Storage Admin role on the project. After a security review, the team wants to restrict it to only read objects in a specific bucket. What should they do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Google Cloud. “ASSOCIATE-CLOUD-ENGINEER” is a trademark of its owner, used for identification only.