Professional Cloud DevOps Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Your enterprise organization is establishing a secure operational framework for service account usage across its development teams. You must configure IAM permissions to support two distinct operational requirements while strictly enforcing the principle of least privilege:
devops-leads@example.com) must be able to impersonate a production deployment service account (prod-deployer@project-id.iam.gserviceaccount.com) from the Google Cloud CLI to obtain short-lived OAuth 2.0 access tokens for emergency rollouts without managing static keys.app-devs@example.com) must be able to provision Compute Engine virtual machines that run workloads under a dedicated workload service account (app-runner@project-id.iam.gserviceaccount.com), but they must not be permitted to directly generate credentials or mint tokens for this workload service account from their local workstations.Which IAM role bindings should you configure?
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.