Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 116 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 116

Select 2Google Cloud Platform

Your organization uses multiple Google Cloud projects to manage different environments (development, staging, production). You are tasked with implementing a secure IAM strategy to ensure proper separation of duties and to minimize the risk of privilege escalation. Which of the following actions should you take to achieve this? (Choose two)

  1. A

    Assign the Owner role to all project administrators to ensure they can manage resources in case of emergencies.

  2. B

    Use predefined roles and custom roles to grant only the permissions necessary for each user's job responsibilities.

  3. C

    Create separate Google Cloud projects for development, staging, and production environments, and assign distinct IAM roles for each environment.

  4. D

    Allow service accounts to act as project editors to streamline automation tasks across all environments.

  5. E

    Enable the principle of least privilege by granting roles at the lowest resource level wherever possible.

Show answer and explanation

Correct answers: B, C

Explanation

To manage privileged roles and enforce separation of duties, it is critical to follow the principle of least privilege and segregate environments with distinct IAM roles. Using predefined and custom roles ensures permissions are tailored to specific job responsibilities, while creating separate projects for different environments prevents accidental or malicious cross-environment access.

  • A. Incorrect.

    Assigning the Owner role to all project administrators is not recommended because it grants excessive permissions, including the ability to modify IAM policies, which increases the risk of privilege escalation.

  • B. Correct.

    Using predefined roles and custom roles to grant only necessary permissions aligns with the principle of least privilege and ensures users have access only to what they need to perform their tasks.

  • C. Correct.

    Creating separate projects for development, staging, and production ensures a clear separation of duties and minimizes the risk of accidental changes affecting critical environments.

  • D. Incorrect.

    Allowing service accounts to act as project editors across all environments violates the principle of least privilege and may expose resources to unnecessary risks.

  • E. Incorrect.

    While enabling the principle of least privilege is a good practice, it is not directly tied to the implementation of separation of duties across multiple environments in this scenario.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam