Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 115 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 115

Select 2Google Cloud Platform

Your organization requires that no single user should have the ability to both manage IAM policies and delete resources in a project to maintain proper separation of duties. Which combination of IAM roles would satisfy this requirement?

  1. A

    Assign the 'Owner' role to one user and the 'Editor' role to another user

  2. B

    Assign the 'Project IAM Admin' role to one user and the 'Project Deleter' custom role to another user

  3. C

    Assign the 'Security Admin' role to one user and the 'Project Editor' role to another user

  4. D

    Create a custom role with 'resourcemanager.projects.delete' permission and assign it to one user, while another user is assigned a role with 'resourcemanager.projects.setIamPolicy' permission

Show answer and explanation

Correct answers: B, D

Explanation

To enforce separation of duties, critical permissions like managing IAM policies ('resourcemanager.projects.setIamPolicy') and deleting resources ('resourcemanager.projects.delete') must not be granted to the same user. Options 2 and 4 achieve this by assigning these responsibilities to separate users through predefined or custom roles, ensuring compliance with best practices for privileged role management.

  • A. Incorrect.

    The 'Owner' role has both IAM management and resource deletion permissions, violating the requirement for separation of duties. Assigning 'Editor' to another user does not address this issue, as 'Owner' still retains all necessary permissions.

  • B. Correct.

    This approach separates the permissions effectively. 'Project IAM Admin' can manage IAM policies, while the 'Project Deleter' custom role ensures resource deletion is handled by a different user.

  • C. Incorrect.

    The 'Security Admin' role is primarily used for managing security policies and does not include resource deletion or IAM management permissions. The 'Project Editor' role includes resource modification but not deletion or IAM management, so this combination does not address the requirement.

  • D. Correct.

    This solution ensures strict separation of duties by creating a custom role for resource deletion (e.g., 'resourcemanager.projects.delete') and assigning the 'resourcemanager.projects.setIamPolicy' permission to another user. This satisfies the requirement to split critical permissions between users.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam