An automation uses a service account and needs to retrieve objects from a Cloud Storage bucket. Your organization enforces least privilege. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: Grant the service account read-only access to the Cloud Storage bucket..
Why this is the answer
Granting the service account read-only access to the Cloud Storage bucket adheres to the principle of least privilege by providing only the necessary permissions for the automation to retrieve objects. This minimizes potential security risks. Granting compute.instanceAdmin to your user account is incorrect because it provides excessive permissions unrelated to Cloud Storage access and applies to your user, not the service account. Granting iam.serviceAccountUser to your user account allows your user to impersonate a service account, but doesn't directly grant the service account permissions to Cloud Storage. Granting the service account the cloud-platform role is incorrect because it provides broad, all-encompassing permissions across all Google Cloud services, violating the principle of least privilege.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed