IAM Practice Questions
Roles, inheritance, service accounts and least privilege. 9 original questions with full explanations.
Question 1 of 9
0 answered · 9 remaining
IAMmedium
An analyst needs to read objects in one Cloud Storage bucket and nothing else. Which grant follows least privilege?
Select an answer to see the explanation.
These questions are written by GCP Prep to test understanding of publicly documented concepts. They are not real exam questions.
What this test covers
One concept per question. If you can explain each of these without hesitating, you are in good shape on IAM.
- Least privilege is both the narrowest role and the narrowest scope
- IAM conditions can bind access to time, resource names or other attributes
- Organisation policy is a preventative control that binds even project administrators
- Workload identity federation eliminates long-lived service account keys
- Attach a purpose-specific service account and grant only the role it needs
- Custom roles exist for when no predefined role is narrow enough
- Separation of duties prevents a single identity holding conflicting powers
- Data access logs record reads and must be enabled deliberately
- Grant to groups so access follows role changes automatically
Other topics
Related Certifications
- Associate Cloud EngineerThe hands-on baseline. The most widely useful place to start.
- Professional Cloud Security EngineerIdentity, boundaries, data protection and compliance.
- Professional Cloud ArchitectThe flagship design exam. Long scenarios, real trade-offs.
- Professional Cloud DeveloperFor engineers who build and ship cloud-native applications.
Related Cloud Topics
- Identity and Access Management (IAM)Who can do what to which resource: members, roles, policy inheritance, service accounts and least privilege.
- Encryption and Key ManagementDefault encryption, customer-managed keys, rotation and secret handling — and the operational consequences of each choice.
- Security Posture and Threat DetectionFinding misconfigurations, detecting threats, understanding audit logs and running a detection and response capability.