An application running on a Compute Engine instance needs to access data in a Cloud Storage bucket. Your team's policy prohibits globally readable buckets and requires adherence to the principle of least privilege.
Which is the correct approach to meet this requirement?