Your organization runs a Cloud Build CI/CD pipeline in Project A that needs to deploy Compute Engine instances in Project B. You want to avoid storing service account keys in the build configuration. What authentication approach should you configure to allow the Cloud Build service account to deploy resources in Project B?
Free ACE - Associate Cloud Engineer Practice Questions
Test your knowledge with 10 free sample practice questions for the ACE - Associate Cloud Engineer certification. Each question includes a detailed explanation to help you learn.
Disclaimer: These are original, AI-generated practice questions created by ProctorPulse for exam preparation purposes. They are not sourced from any official exam and are not affiliated with or endorsed by Google Cloud. Use them as a study aid alongside official preparation materials.
An organization is using a Google Cloud service account for a data processing application. The application only needs to read data from a specific Cloud Storage bucket. How should you configure the IAM policy for the service account to follow the principle of least privilege?
What approach should the team adopt to authenticate the Cloud Function during local testing while maintaining security best practices?
A new application needs to access data stored in a cloud storage bucket. You have created a service account for this application. Which role should you assign to the service account to ensure it can read data from the bucket without granting unnecessary permissions?
After reviewing the access logs, which sequence of actions would establish the minimum required permissions for this service account while maintaining operational continuity?
What is the primary purpose of a service account in a cloud project?
A service account is unable to access a certain cloud storage bucket, despite being configured with a role that should allow access. What would be the most effective step to diagnose the issue?
Your team has deployed a data processing application on a Compute Engine instance that needs to retrieve log files stored in a Cloud Storage bucket. What approach should you use to enable the application to authenticate and access the bucket contents?
(Select all that apply) You are configuring access for three containerized microservices deployed on Google Kubernetes Engine. Service A handles user analytics and writes to BigQuery datasets. Service B processes messages from Pub/Sub and stores summaries in Cloud SQL. Service C reads from BigQuery for reporting purposes only. Which configurations properly implement least privilege access control?
(Select all that apply)
What should you configure to allow a team member to temporarily access a cloud resource using service account impersonation?

