Google Associate Cloud Engineer exam dumps

Google Associate Cloud Engineer practice question 359 of 375

Associate Cloud Engineer. Free level, Google Cloud. Free question with the correct answer and a full explanation.

Google Associate Cloud Engineer Question 359

Single answerGoogle Cloud Platform

You are managing a Google Cloud project where different services need to interact securely. You have created a new Compute Engine instance that requires access to a Cloud Storage bucket to read and write data. How should you assign a service account to this instance to ensure it has the appropriate permissions?

  1. A

    Assign the Compute Engine default service account to the instance without any additional roles.

  2. B

    Create a new service account with the 'Storage Admin' role and assign it to the instance.

  3. C

    Use the 'App Engine default service account' and assign it to the instance.

  4. D

    Assign the instance to a new service account with the 'Storage Object Viewer' role.

Show answer and explanation

Correct answer: B

Explanation

To securely grant a Compute Engine instance the ability to read and write to a Cloud Storage bucket, you should create a new service account with the 'Storage Admin' role. This ensures the instance has the appropriate permissions necessary for both reading and writing operations on the Cloud Storage bucket. Assigning the correct roles to the service account is crucial to maintaining the principle of least privilege while meeting the operational requirements.

  • A. Incorrect.

    Using the Compute Engine default service account without additional roles might not provide the necessary permissions for accessing the Cloud Storage bucket.

  • B. Correct.

    Creating a new service account with the 'Storage Admin' role and assigning it to the instance grants both read and write access to the Cloud Storage bucket, which is necessary for the required operations.

  • C. Incorrect.

    The App Engine default service account is typically used for App Engine applications and might not have the necessary permissions for a Compute Engine instance to interact with Cloud Storage.

  • D. Incorrect.

    Assigning the instance to a service account with the 'Storage Object Viewer' role only provides read access and does not allow writing to the Cloud Storage bucket.

Timed practice exam

Take a Google Associate Cloud Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam