Objective 4.1
ACEManaging IAM
Objective 4.1 sits in Configuring access and security, which carries 20% of the Associate Cloud Engineer exam. The questions below are original, written from the official objective title above, and each explanation cites the Google Cloud page it rests on.
Objective title verbatim from the official objectives. Google Cloud exam page ↗
A worked example
Shown solved, with the whole explanation open: this is what every question here carries.
An engineer reads the permission compute.instances.list and asks how IAM permission names are structured. What is the format?
Correct.
Concept
A permission name reads from the broadest scope inward, which is what lets a whole service or a whole resource type be matched with a prefix. The action comes last because it is the narrowest part.
Why C
IAM permissions take the form service.resource.verb, and they usually correspond one to one with the REST methods of the service that defines them.
Now you: objective 4.1 questions
No account needed. The explanation opens when you answer.
Sample question 1 of 3
A team keeps hitting a ceiling while creating custom roles. How many custom roles does IAM allow in one project?
Sample question 2 of 3
An analyst comparing role metadata sees an ETag of AA== on several roles. Which roles always carry that value?
Sample question 3 of 3
A team creates a custom role in one project and tries to grant it on a second project. What does IAM allow?
Full Associate Cloud Engineer question bank coming
We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.
Read the sources
These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.