Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 119 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 119

Select 2Google Cloud Platform

Your organization uses Google Cloud and wants to enforce the principle of least privilege while managing IAM roles. A critical application requires a Cloud Storage bucket administrator and a separate identity to audit bucket access logs. How should you configure IAM roles to ensure both security and compliance with separation of duties?

  1. A

    Assign the Storage Object Admin role to the application service account and the Logs Viewer role to the auditor.

  2. B

    Assign the Owner role to the application service account and the Storage Admin role to the auditor.

  3. C

    Assign the Storage Admin role to the application service account and the Logs Viewer role to the auditor.

  4. D

    Create a custom role with both 'storage.buckets.update' and 'logging.logEntries.list' permissions, and assign it to the application service account.

  5. E

    Assign the Storage Admin role to the application service account and create a custom role for the auditor with 'logging.logEntries.list' permission.

Show answer and explanation

Correct answers: C, E

Explanation

Separation of duties ensures that no single identity has excessive control or oversight in critical operations. Assigning the Storage Admin role to the application service account allows it to manage Cloud Storage buckets without over-privileging. For the auditor, either the Logs Viewer role or a custom role with 'logging.logEntries.list' permission ensures that their access is limited to log auditing, enforcing the principle of least privilege and maintaining security best practices.

  • A. Incorrect.

    This option violates the principle of least privilege, as the Storage Object Admin role grants permissions beyond what is required for managing the bucket. The Logs Viewer role is appropriate for an auditor, but this setup doesn't fully align with separation of duties.

  • B. Incorrect.

    The Owner role is overly permissive and violates the principle of least privilege. Assigning the Storage Admin role to the auditor is inappropriate because it grants permissions unrelated to auditing.

  • C. Correct.

    This follows best practices by assigning the Storage Admin role to the application service account for bucket management and the Logs Viewer role to the auditor for reviewing logs, ensuring separation of duties.

  • D. Incorrect.

    Creating a single custom role that combines permissions for both storage management and log auditing violates the separation of duties principle.

  • E. Correct.

    This approach appropriately assigns the Storage Admin role to the application service account for managing the bucket and uses a custom role to restrict the auditor's permissions to only listing log entries, ensuring both least privilege and separation of duties.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam