A third‑party app on a new Compute Engine VM must access installation files in Cloud Storage while other VMs must not. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a new service account, attach it to the VM, and grant that service account Cloud Storage permissions..
Why this is the answer
Creating a new service account, attaching it to the VM, and granting specific Cloud Storage permissions is the most secure and granular approach. This follows the principle of least privilege, ensuring only the necessary VM has access to the Cloud Storage files. The Compute Engine default service account often has broad permissions, which is not ideal for a single application requiring specific access, and modifying its permissions could inadvertently affect other VMs. Adding metadata to Cloud Storage objects does not control access; it's used for object categorization or information, not security.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed