Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 123 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 123

Single answerGoogle Cloud Platform

Your organization uses a Google Cloud Storage bucket to store sensitive financial data. You are tasked with ensuring that the least privilege principle is followed while granting access to this bucket. A junior engineer suggests using IAM roles for access control, while another engineer suggests using ACLs. What should you do to properly secure the bucket?

  1. A

    Use IAM roles to grant access to users and groups, and avoid using ACLs unless absolutely necessary.

  2. B

    Use ACLs to define fine-grained access for each individual user, and avoid using IAM roles.

  3. C

    Combine IAM roles and ACLs equally to ensure both coarse-grained and fine-grained access control.

  4. D

    Grant the 'Storage Admin' IAM role to all users who need access to the bucket, and disable ACLs entirely.

Show answer and explanation

Correct answer: A

Explanation

In Google Cloud, IAM roles are the recommended method for managing access control as they provide centralized, coarse-grained permission management. ACLs are considered legacy and should only be used in edge cases where fine-grained access control is required. By using IAM roles and avoiding ACLs unless necessary, you can ensure the least privilege principle is followed and minimize potential security risks.

  • A. Correct.

    This is the correct approach. IAM roles are the recommended way to manage access in Google Cloud as they offer centralized and scalable access control. ACLs should only be used in specific use cases where fine-grained control is absolutely necessary.

  • B. Incorrect.

    This is incorrect because ACLs are not the primary mechanism for access control in Google Cloud. They are legacy tools and should be avoided unless there is a specific requirement.

  • C. Incorrect.

    This is incorrect because combining IAM roles and ACLs equally can lead to confusion and misconfigurations, making it harder to maintain the principle of least privilege.

  • D. Incorrect.

    This is incorrect because granting the 'Storage Admin' role to all users violates the principle of least privilege. Additionally, disabling ACLs entirely might not address all use cases.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam