Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 39 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 39

Select 2Google Cloud Platform

Your organization is setting up a Shared VPC environment in Google Cloud where multiple service projects will connect to a single host project. As the network administrator, you need to ensure that IAM roles are appropriately assigned to allow users in the service projects to create and manage resources (e.g., VMs and GKE clusters) while maintaining proper network isolation and security. Which of the following IAM roles should you assign to achieve this?

  1. A

    Network Admin role on the Shared VPC host project for users in service projects

  2. B

    Shared VPC Admin role on the Shared VPC host project for users in service projects

  3. C

    Compute Admin role on the service projects for users in those projects

  4. D

    Compute Network User role on the Shared VPC host project for users in service projects

  5. E

    Security Admin role on the Shared VPC host project for users in service projects

Show answer and explanation

Correct answers: B, D

Explanation

In a Shared VPC environment, the Shared VPC Admin role is required for managing the Shared VPC host project and delegating subnet access to service projects. The Compute Network User role allows service project users to attach resources to the Shared VPC network, ensuring they can use the network without having excessive permissions. Together, these roles provide the necessary access while adhering to the principle of least privilege.

  • A. Incorrect.

    The Network Admin role provides full control over networking in the project, including creating and modifying networks and subnets. Assigning this role at the host project level to service project users would violate the principle of least privilege, as it grants excessive permissions.

  • B. Correct.

    The Shared VPC Admin role is specifically designed for managing the Shared VPC host project, which includes delegating subnet usage to service projects. This is the correct role to allow service project users to access the Shared VPC network resources.

  • C. Incorrect.

    The Compute Admin role grants permissions to manage compute resources at the project level. Assigning this role on the service projects is not required for managing Shared VPC resources, as it does not control network access.

  • D. Correct.

    The Compute Network User role allows users to attach network interfaces to instances and manage network resources in the Shared VPC. This role is essential for enabling service project users to use the Shared VPC network without excessive permissions.

  • E. Incorrect.

    The Security Admin role grants permissions to manage security policies and firewall rules. While it might be useful for advanced security management, it is not required to enable basic Shared VPC functionality for service project users.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam