Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 118 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 118

Select 4Google Cloud Platform

Your organization is using Google Cloud to host a critical application. To maintain security best practices, you need to ensure that no single individual has excessive privileges that could lead to a security risk or accidental misconfiguration. You decide to implement separation of duties for managing the application. Which of the following actions should you take to achieve this?

  1. A

    Assign separate IAM roles for resource management and security operations to different individuals.

  2. B

    Grant the Owner role to a single user who will oversee both security and resource management.

  3. C

    Use predefined IAM roles such as 'Editor' for general users and 'Security Admin' for security-specific tasks.

  4. D

    Create custom IAM roles with limited permissions tailored to the specific responsibilities of each team.

  5. E

    Enable the principle of least privilege by granting only the necessary permissions to each user.

Show answer and explanation

Correct answers: A, C, D, E

Explanation

To enforce separation of duties, it is important to avoid assigning excessive or overlapping privileges to individuals. Assigning separate roles for different responsibilities, leveraging predefined roles, using custom roles where necessary, and adhering to the principle of least privilege are all key steps to achieving this. Combining these strategies minimizes the risk of privilege misuse, strengthens security, and ensures compliance with best practices for managing IAM roles in Google Cloud.

  • A. Correct.

    Correct. Assigning separate IAM roles for resource management and security operations ensures separation of duties, reducing the likelihood of a single individual having excessive permissions.

  • B. Incorrect.

    Incorrect. Granting the Owner role to a single user violates separation of duties as this role has broad and unrestricted access to resources.

  • C. Correct.

    Correct. Using predefined IAM roles such as 'Editor' and 'Security Admin' aligns permissions to specific responsibilities, helping enforce separation of duties.

  • D. Correct.

    Correct. Creating custom IAM roles tailored to specific responsibilities ensures that users only have the permissions they need for their tasks, preventing unnecessary access.

  • E. Correct.

    Correct. The principle of least privilege is a critical security practice that ensures users only have the minimum permissions required to perform their functions, supporting separation of duties.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam