makeporngreatagain.pro
yeahporn.top
hd xxx

Practice Test 1 | Google Cloud Certified Associate Cloud Engineer | Dumps | Mock Test

111,247

While working on a project, an application administrator has been given the responsibility of managing all resources. He wants to delegate the responsibility of managing the existing service accounts to another administrator. He will also be responsible to manage the other service accounts that will be created. Which of the following is the best way to delegate the privileges required to manage all the service accounts?

A. Granting iam.serviceAccountUser to the administrator at the project level

B. Granting iam.serviceProjectAccountUser to the administrator at the project level

C. Granting iam.serviceAccountUser to the administrator at the service account level

D. Granting iam.serviceProjectAccountUser to the administrator at the service account level

Explanation:

Correct Answer – Option A

The service account user role (iam.serviceAccountUser) for all service accounts in a project can be granted at the project level. While the service account user role for a specific service account in a project can be granted at the service account level. So, as per given scenario, to delegate the privileges to manager all the service accounts, service account user role (iam.serviceAccountUser) will be granted to the administrator at the project level.

Option A is correct. A user can manage all the service accounts in the project if service account user role iam.serviceAccountUser is granted to him at the project level. Also, whenever a new service account will be created, the administrator will be granted iam.serviceAccountUser automatically for that new service account.

Option B is incorrect. iam.serviceProjectAccountUser is not a service account user role in Google Cloud.

Option C is incorrect. Granting iam.serviceAccountUser to the administrator at the service account level means the service account user role is granted for a specific account. It will enable him to manage that specific service account in the project, not all the service accounts. It will require setting the role for all service accounts separately. Also, If a new service account will be created, the administrator will have to grant iam.serviceAccountUser to the other administrator.

Option D is incorrect. iam.serviceProjectAccountUser is not a service account user role in Google Cloud.

Reference:

Google Cloud Identity and Access Management – Service Accounts

https://cloud.google.com/iam/docs/service-accounts

Comments are closed, but trackbacks and pingbacks are open.

baseofporn.com https://www.opoptube.com
Ads Blocker Image Powered by Code Help Pro

Ads Blocker Detected!!!

We have detected that you are using extensions to block ads. Please support us by disabling these ads blocker.