An engineer wants to view the current IAM policy for a project in JSON format. Which command should they use?
This is the exact, valid CLI command for retrieving a project's IAM policy. The subcommand get-iam-policy reads the IAM policy bound to the specified project resource, and --format json renders it as a JSON array of bindings, including roles, members, and conditions. It is the correct tool for this task.
Why this answer
The command 'gcloud projects get-iam-policy my-project --format json' retrieves the IAM policy bound to a project and outputs it in JSON. This is the correct gcloud command for viewing a project's IAM policy, which lists bindings between members and roles. The --format json flag ensures machine-readable JSON output.
Exam trap
The trap is confusing project metadata retrieval (describe) with IAM policy retrieval (get-iam-policy), or assuming a generic 'iam policies get' command exists — ACE tests precise command syntax and resource scope.
How to eliminate wrong answers
Option A is wrong because 'gcloud resource-manager folders get-iam-policy' operates on folders, not projects, and 'my-project' is a project ID — the command would fail or target the wrong resource hierarchy level. Option B is wrong because 'gcloud projects describe' returns project metadata (name, ID, number, lifecycle state), not the IAM policy. Option D is wrong because 'gcloud iam policies get' is not a valid gcloud command — IAM policies are retrieved via resource-specific get-iam-policy commands, not a generic iam policies get.