Google Cloud Platform Interview Questions
27 questions
GCP interview questions covering IAM (Workload Identity, service account security, org policy versus IAM), Cloud Functions (cold starts, Pub/Sub delivery semantics, Gen 1 versus Gen 2 concurrency), and Cloud Storage (access control, signed URLs, lifecycle management, exposure alerting) — scenario-driven, matching the same depth as this site's AWS coverage rather than treating GCP as an afterthought.
How would you audit an entire GCP organization to find every principal holding Owner or Editor at the project level, before a security review?
AdvancedGCP7 min
Why is granting a GCP Editor or Owner basic role considered dangerous, and how do predefined and custom roles fix that?
BeginnerGCP6 min
How would you grant a contractor temporary access to a GCP project that automatically expires, without manually revoking it later?
IntermediateGCP6 min
A service account in Project A needs to read from a Cloud Storage bucket in Project B — how does IAM actually handle this cross-project access?
IntermediateGCP6 min
A GCP service account key was accidentally committed to a public repository — walk through your incident response, GCP-specific steps included.
AdvancedGCP8 min
How would you design least-privilege IAM for a Cloud Function that reads from Pub/Sub and writes to a specific Cloud Storage bucket?
IntermediateGCP6 min
A project has correct IAM roles, but you still need to guarantee no VM ever gets a public IP — is that an IAM problem, or something else?
IntermediateGCP6 min
How would you design a CI/CD pipeline's GCP authentication using service account impersonation instead of a downloaded key, and why is that safer?
AdvancedGCP7 min
A GKE workload needs to call a GCP API — should it use Workload Identity or a mounted service account key file, and why?
IntermediateGCPGKE7 min