Q: 10
A batch job running on Compute Engine needs temporary write access to a Cloud Storage bucket.
You want the batch job to use the minimum permissions necessary to complete the task. What
should you do?
Options
Discussion
Yeah, B lines up with least privilege since storage.objectCreator gives just enough rights for writing. No need for full admin or managing keys. I think it’s pretty standard practice, but let me know if you see a catch I missed.
I don’t think D fits since it’s extra steps, B makes more sense for just giving write access to the bucket.
B , seen similar question in practice sets, minimum privilege with storage.objectCreator fits here.
Be respectful. No spam.