☎  076 959 6407✉  support@quizcrazepro.co.za
Learn. Practice. Build your future.
BlogHelpContact
G

Google Professional Cloud Security Engineer Actual Exam Questions

318 Questions120 Minutes70% Passing Score▣ Updated: Sep 2026

Question 15 of 318

Single answer
An application running on a Compute Engine instance needs to read data from a Cloud Storage bucket. Your team does not allow Cloud Storage buckets to be globally readable and wants to ensure the principle of least privilege.
Which option meets the requirement of your team?
ACreate a Cloud Storage ACL that allows read-only access from the Compute Engine instance's IP address and allows the application to read from the bucket without credentials.
BUse a service account with read-only access to the Cloud Storage bucket, and store the credentials to the service account in the config of the application on the Compute Engine instance.
CUse a service account with read-only access to the Cloud Storage bucket to retrieve the credentials from the instance metadata.
DEncrypt the data in the Cloud Storage bucket using Cloud KMS, and allow the application to decrypt the data with the KMS key.
Correct Answer: C

Use a service account with read-only access to the Cloud Storage bucket to retrieve the credentials from the instance metadata.

Explanation

The correct answer is highlighted above. Review the wording carefully, then use the next question to continue building your understanding of Google certification topics.

About this practice exam

Review 318 Google questions with answers and explanations. Use the navigation to move through the exam at your own pace.