You store documents in Cloud Storage and need to let users share files with external people for a configurable time period, after which access is revoked. How should you configure Cloud Storage?
Choose an answer
Tap an option to check your answer.
Correct answer: Generate a signed URL for each shared document with an expiration time..
Why this is the answer
Generating a signed URL for each shared document with an expiration time is the correct approach because it allows temporary, time-limited access to specific objects without requiring a Google account or granting permanent permissions. The URL contains authentication information and an expiration timestamp, ensuring access is automatically revoked. Creating signed policy documents is for controlling uploads or form posts, not for sharing existing objects. Applying ACL permissions directly would grant permanent access, not temporary. Granting the Storage Object Viewer role to all authenticated users would give broad, permanent access to all objects in the bucket, which is not suitable for time-limited sharing with external, unauthenticated users.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed