Google Cloud Associate Cloud Engineer — Question 8

You need to set up permissions for a set of Compute Engine instances to enable them to write data into a particular Cloud Storage bucket. You want to follow
Google-recommended practices. What should you do?

Answer options

Correct answer: C

Explanation

The correct answer is C because assigning the IAM role 'storage.objectCreator' allows the service account to write objects to the specified Cloud Storage bucket, which is the intended purpose. Option A provides limited write access, while option B grants broader permissions that may not be necessary. Option D gives too much access, allowing deletion and modification of objects, which exceeds the requirement.