Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 125 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 125

Select 2Google Cloud Platform

Your company wants to secure access to a Google Cloud Storage bucket containing sensitive financial data. The security team has mandated that only members of the 'finance-team' group should have access to this bucket. However, one specific team member, due to compliance reasons, should only have read access, while the rest of the team should have read and write access. How should you configure permissions to meet these requirements?

  1. A

    Assign the 'roles/storage.admin' role to the 'finance-team' group at the bucket level.

  2. B

    Assign the 'roles/storage.objectViewer' role to the specific team member at the bucket level.

  3. C

    Assign the 'roles/storage.objectAdmin' role to the 'finance-team' group at the bucket level.

  4. D

    Use an Access Control List (ACL) to grant 'READER' permission to the specific team member and 'OWNER' permission to the 'finance-team' group.

  5. E

    Assign the 'roles/storage.legacyBucketWriter' role to the 'finance-team' group.

Show answer and explanation

Correct answers: B, C

Explanation

To meet the requirements, you should use IAM roles to manage access to the bucket. Assigning 'roles/storage.objectViewer' to the specific team member ensures they only have read access. Assigning 'roles/storage.objectAdmin' to the 'finance-team' group provides the rest of the team with read and write access. This approach aligns with best practices, as it uses IAM roles instead of legacy roles or ACLs, ensuring a simpler and more secure permission model.

  • A. Incorrect.

    This role gives full administrative permissions to the bucket, which exceeds the required level of access. It is not the best practice to grant overly permissive roles when more specific roles can achieve the same goal.

  • B. Correct.

    This role allows the specific team member to have read-only access to the objects within the bucket, fulfilling the compliance requirement.

  • C. Correct.

    This role grants the 'finance-team' group the ability to read and write objects within the bucket. It is the appropriate level of access for the majority of the group's needs.

  • D. Incorrect.

    Using ACLs is an older access control method and is generally not recommended when Identity and Access Management (IAM) roles can meet the requirements. Additionally, ACLs can lead to complex and error-prone permission configurations.

  • E. Incorrect.

    This role is a legacy role that provides write access to the bucket but does not provide object-level permissions. It is not suitable for securing access to objects in modern use cases.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam