NEW
Font size
WorksheetsModule 2 - Identity & Access Management
Total questions: 7
Worksheet time: 4mins
A multinational company adopts Google Cloud for its enterprise workloads. The cloud security engineer configures IAM roles to follow the principle of least privilege. The team needs to identify how IAM members are authenticated across different identity types. Which identities do Google Cloud IAM members use to access resources?
For Google Account, Google group, and service account → domain name; for G Suite and Cloud Identity domain → email address
For Google Account, Google group, and service account → email address; for G Suite and Cloud Identity domain → domain name
For Google Account, Google group, and G Suite → domain name; for service account and Cloud Identity domain → email address
For Google Account, Google group, and G Suite → email address; for service account and Cloud Identity domain → domain name
A developer launches an application on an AWS EC2 instance that needs to retrieve images from an S3 bucket. The admin creates a service role with a trust policy that allows the instance to assume the role and a permission policy granting read-only access to the S3 bucket. The application uses the temporary credentials provided by the role. In this scenario, must the developer manage credentials or request additional permissions from the admin?
A senior cloud engineer, Ava, advises her company's leadership to migrate all applications to a public cloud. After the migration, Ava's team must be able to configure, monitor, and maintain the new cloud platform and applications. Which component of a cloud platform provides these tools and interfaces?
Physical and Environmental Component
Compute Component
Management Component
Virtualization Component
A cloud administrator must create separate subscriptions for each division in Azure but ensure consistent IAM role assignments across all. He needs an automated, repeatable method for provisioning identity and access resources at scale. Which service should he use?
A. Azure AD Privileged Identity Management
B. Azure AD Multi-Factor Authentication
C. Azure AD Identity Protection
D. Azure AD Self-Service Password Reset
Aria is an IT manager at a company that wants to define infrastructure resources like IAM policies, EC2 instances, and networking in reusable templates to reduce human error and enforce consistent access control. Which AWS service should Aria use?
AWS CloudFormation
AWS Config
AWS Inspector
AWS Control Tower
A global enterprise wants to automate provisioning of complex resource stacks including VPCs, IAM roles, and multi-tier applications. They require version-controlled, template-driven infrastructure that scales across regions. Which service meets this need?
AWS OpsWorks
AWS CloudFormation
AWS Config
AWS Organizations
A DevOps team at a large company wants to automatically deploy IAM policies and resource stacks across multiple AWS accounts with minimal manual intervention. They also want rollback capability if a deployment fails. Which service should they use?
AWS Config
AWS Control Tower
AWS CloudFormation
AWS IAM
