Google Cloud Associate Cloud Engineer — Question 64

You are using Container Registry to centrally store your company's container images in a separate project. In another project, you want to create a Google
Kubernetes Engine (GKE) cluster. You want to ensure that Kubernetes can download images from Container Registry. What should you do?

Answer options

Correct answer: A

Explanation

The correct answer, A, is valid because granting the Storage Object Viewer IAM role allows the Kubernetes nodes to pull images from Container Registry. Option B is incorrect as allowing full access to Cloud APIs does not specifically grant access to Container Registry. Option C is not necessary since configuring a service account and using a P12 key adds complexity without addressing the direct permission needed. Option D is also incorrect because setting ACLs on individual images is not the best practice compared to using IAM roles.