Google Professional Cloud DevOps Engineer exam dumps

Google Professional Cloud DevOps Engineer practice question 184 of 268

Professional Cloud DevOps Engineer. Associate level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud DevOps Engineer Question 184

Select 2Google Cloud Platform

Your organization manages multiple projects in Google Cloud, and you are tasked with ensuring that only specific groups of users can create Compute Engine instances across all projects, while also restricting others from modifying organization-level settings. Which combination of IAM roles and policies will best achieve this requirement?

  1. A

    Assign the 'Compute Admin' role to the specific user group at the project level.

  2. B

    Apply an organization policy to restrict modifications to organization-level settings.

  3. C

    Assign the 'Owner' role to the specific user group at the organization level.

  4. D

    Use the 'Compute Instance Admin (v1)' role at the project level for the specific user group.

  5. E

    Apply a custom role combining 'Compute Admin' and 'Security Admin' roles at the organization level.

Show answer and explanation

Correct answers: B, D

Explanation

To meet the requirements, you need a combination of fine-grained IAM roles and organization-level policies. The 'Compute Instance Admin (v1)' role provides the necessary permissions for managing Compute Engine instances without overprivileging users, while the organization policy ensures that sensitive settings at the organization level are protected from unwanted changes. This approach adheres to the principle of least privilege and ensures security best practices are followed.

  • A. Incorrect.

    This option is incorrect because the 'Compute Admin' role grants permissions to manage all Compute Engine resources, but it is overly permissive if applied at the project level and does not address the restriction on organization-level settings.

  • B. Correct.

    This is correct because applying an organization policy to restrict modifications ensures that sensitive organization-level settings cannot be altered while adhering to security best practices.

  • C. Incorrect.

    This option is incorrect because assigning the 'Owner' role at the organization level grants excessive permissions, including the ability to modify organization-level settings, which violates the requirement to restrict such changes.

  • D. Correct.

    This is correct because the 'Compute Instance Admin (v1)' role provides fine-grained permissions for managing instances without granting excessive privileges, and applying it at the project level ensures the specific group can create instances without affecting other resources.

  • E. Incorrect.

    This option is incorrect because creating a custom role combining 'Compute Admin' and 'Security Admin' roles at the organization level would grant excessive permissions and does not align with the principle of least privilege.

Timed practice exam

Take a Google Professional Cloud DevOps Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam