Back to Must-Know Dashboard

MongoDB

Must-Know Practice Sets

Overall Progress0 / 5 Modules Completed
Identity and Access Management#1

Which role provides extensive visibility and control over all resources within a company's Google Cloud Platform?

A
Domain Administrator
B
Project Creator
C
Organization Admin
D
Network Admin

The Organization Admin role provides extensive visibility and control over all resources within a GCP organization.

Identity and Access Management#2

How do folders facilitate administration rights delegation in GCP?

A
Folders allow delegation of ownership to specific department heads
B
Each folder can have only one administrator
C
They don't permit delegation of administrative rights
D
Administrators at the organization level control all folders

Folders in GCP allow resource organization and delegation of administrative rights, such as ownership, to specific departments or teams.

Identity and Access Management#3

Which principle guides the granting of roles in Cloud IAM for GCP resources?

A
Privilege based on resource count
B
Least privilege required
C
Privilege based on organizational hierarchy
D
Maximum privilege required

The principle of least privilege states that users should only be granted the minimum permissions necessary to perform their tasks.

Identity and Access Management#4

What happens to the Platform APIs service account when a GCP project is deleted?

A
The service account is also deleted, along with the project
B
Roles granted to this account cannot be changed
C
The account is retained, but access is revoked for the deleted project
D
It remains active for future projects

For certain managed or cross-project service accounts, the account itself may be retained while its access bindings to the deleted project are revoked.

Identity and Access Management#5

How can organizations effectively manage permissions for individual users?

A
Directly assign roles to users
B
Assign all permissions to all users
C
Avoid role assignments
D
Use groups for role assignments

It is a best practice to assign roles to Google Groups rather than individual users. This simplifies access management as users can be added or removed from groups without needing to update IAM policies.

Identity and Access Management#6

Why is it considered a best practice to have more than one owner for a Google Cloud project?

A
Single ownership simplifies project management.
B
It ensures restricted access to project resources.
C
Sole ownership can lead to accidental project deletion.
D
Multiple owners allow easier project deletion.

If a project has only one owner and their account is compromised, disabled, or deleted, the project could be orphaned or accidentally deleted. Having multiple owners ensures continuity of access and management.

Identity and Access Management#7

How can you effectively track and manage service accounts in GCP?

A
Avoid assigning display names to maintain anonymity
B
Implement a consistent naming convention for service accounts
C
Use default naming provided by GCP for service accounts
D
Assign random display names to service accounts for anonymity

Implementing a consistent naming convention and descriptive display names for service accounts makes it easier to track their purpose, ownership, and permissions across a Google Cloud environment.

Identity and Access Management#8

Where do Cloud IAM roles granted at the organization level apply within the GCP resource hierarchy?

A
Only to projects directly under the organization
B
To all resources within the organization
C
Only to resources within a project
D
Only to the organization itself

In Google Cloud, IAM policies are inherited downwards through the resource hierarchy. Roles granted at the Organization level apply to all folders, projects, and resources within that organization. The original answer 'Only to projects directly under the organization' is incorrect.

Identity and Access Management#9

What role facilitates trusted users to utilize a service account in GCP?

A
IAM Manager
B
Project Admin
C
ServiceAccountUser
D
Resource Owner

The roles/iam.serviceAccountUser role allows a user to impersonate and run operations as a service account, effectively utilizing it for resources like Compute Engine instances.

Identity and Access Management#10

What is required to enable access via access scopes in a project?

A
Cloud IAM Permissions
B
Enabled API
C
Service Account Keys
D
Access Policies

Access scopes are used to specify the API access for a Compute Engine instance. The corresponding API must be enabled in the project for the access scope to function properly.

Master the remaining 74 Must-Know questions

You've seen the basics. Unlock the full database of verified simulations and guarantee your selection with the 2026 Success Pass.

Unlock Success Pass — ₹99

Key Topics to Study

Based on our question bank analysis, master these concepts to score high in MongoDB.

Recommended

Success Primer Exam

Test your knowledge under real exam conditions with our curated mock assessment.

Start Preparing for Primers
Watch Walkthroughs!