A CI/CD server fails to perform Google Cloud actions in a project due to permissions. How do you validate the service account's roles for that project?
Choose an answer
Tap an option to check your answer.
Correct answer: In the Cloud Console, view IAM bindings to see which roles are granted to the service account at project, folder, or organization level..
Why this is the answer
The most direct way to validate a service account's permissions is to view its IAM bindings. IAM (Identity and Access Management) defines who has what access to which resources. By checking the IAM page in the Cloud Console, you can see the specific roles granted to the service account at the project level, or inherited from folder or organization levels, which directly dictate its capabilities. "Open Organization Policies" is incorrect because Organization Policies define constraints on resource configurations, not direct access permissions for service accounts. "Use the Console to run an access query" is not a standard or direct feature in the Cloud Console for listing a service account's roles. While audit logs can show why a permission was denied, they don't show what permissions the service account does have, which is what the question asks to validate.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed