A company needs to control access to its API endpoints. Which IAM role should they assign?
AViewer
BEditor
CService Account User
DAPI Consumer
Explanation
The API Consumer role is specifically designed for controlling API access; the others have broader, less specific permissions.
Q432
What happens when you set a firewall rule with 'deny all' first?
AAll traffic is allowed thereafter.
BOnly specific allows will work.
CInbound traffic is completely blocked.
DOutbound traffic is affected only.
Explanation
Setting a 'deny all' rule will block all inbound traffic unless overridden by higher-priority allow rules; options A, B, and D are incorrect interpretations.
Q433
Which service enables private Google access for VMs in a VPC?
APrivate Service Access
BVPN Gateway
CCloud IAM
DCloud Router
Explanation
Private Service Access allows VMs to access Google services privately; other options don't provide this functionality.
Q434
A company needs to control network traffic between different VPC networks. What should they use?