Google Professional Cloud DevOps Engineer exam dumps

Google Professional Cloud DevOps Engineer practice question 10 of 268

Professional Cloud DevOps Engineer. Associate level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud DevOps Engineer Question 10

Single answerGoogle Cloud Platform

Your organization has a Google Cloud project that hosts sensitive data. To meet compliance requirements, you need to ensure that only specific teams can create service accounts within the project, and no one else in the organization can perform this action. Which approach should you take?

  1. A

    Assign the Service Account Admin role at the organization level to the specific teams.

  2. B

    Assign the Service Account Admin role at the project level to the specific teams and set an organization-level policy to deny the role to all other members.

  3. C

    Create a custom IAM role with permissions to manage service accounts and assign it to the specific teams at the project level.

  4. D

    Use an organization-level policy to restrict service account creation and add an exception for the specific teams.

Show answer and explanation

Correct answer: B

Explanation

To meet the compliance requirement, the Service Account Admin role should only be granted to specific teams at the project level, ensuring they have the appropriate permissions within the scope of the project. Additionally, an organization-level policy denying the Service Account Admin role to all other members ensures that no one else in the organization can override this restriction. This approach adheres to the principle of least privilege and provides a robust compliance solution.

  • A. Incorrect.

    Assigning the Service Account Admin role at the organization level to the specific teams would grant them permissions to manage service accounts across all projects in the organization, which violates the principle of least privilege.

  • B. Correct.

    Assigning the Service Account Admin role at the project level to the specific teams ensures they can create and manage service accounts for only that project. The organization-level policy further enforces compliance by denying the role to all other members globally.

  • C. Incorrect.

    Creating a custom IAM role is an option, but it would require additional configuration and does not address organization-wide restrictions for other users. It also adds unnecessary complexity when a predefined role already exists.

  • D. Incorrect.

    Using an organization-level policy to restrict service account creation is a good practice, but policies cannot directly implement exceptions for specific users or groups. You would need to manage permissions at the project level instead.

Timed practice exam

Take a Google Professional Cloud DevOps Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam