Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 120 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 120

Select 3Google Cloud Platform

Your organization is using Google Cloud Storage to store sensitive files. The security team has identified that some developers are unintentionally accessing files they should not have access to. You are tasked with ensuring that only specific users can access certain files. Which of the following actions should you take to enforce the principle of least privilege while managing IAM permissions and access control lists (ACLs)?

  1. A

    Replace the current ACLs with IAM roles to manage access at the bucket level.

  2. B

    Use IAM roles in combination with ACLs to manage fine-grained access to specific objects.

  3. C

    Grant 'Storage Object Viewer' role at the project level to all developers to simplify access management.

  4. D

    Review and remove any overly permissive ACL entries granting 'allAuthenticatedUsers' or 'allUsers' access.

  5. E

    Create a custom IAM role with only the necessary permissions and assign it to the developers who need file access.

Show answer and explanation

Correct answers: B, D, E

Explanation

To enforce the principle of least privilege, it is important to combine IAM roles and ACLs effectively for fine-grained access control, remove overly permissive entries, and use custom IAM roles tailored to specific needs. Granting broad permissions at the project level would increase the risk of unauthorized access and is not recommended.

  • A. Incorrect.

    Replacing ACLs with IAM roles entirely may not be appropriate if fine-grained access is needed for specific objects within a bucket. ACLs can still be useful for object-level permissions.

  • B. Correct.

    Using IAM roles in combination with ACLs allows you to manage access at both the bucket and object levels, ensuring fine-grained access control.

  • C. Incorrect.

    Granting 'Storage Object Viewer' at the project level would violate the principle of least privilege, as it provides unnecessary access to all objects in all buckets within the project.

  • D. Correct.

    Removing overly permissive ACL entries such as 'allAuthenticatedUsers' or 'allUsers' is critical to prevent unauthorized access to sensitive files.

  • E. Correct.

    Creating a custom IAM role with only the required permissions ensures developers have access only to what they need, adhering to the principle of least privilege.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam