Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 128 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 128

Select 2Google Cloud Platform

Your organization uses Google Cloud for managing resources and has several teams working on different projects. The security team has mandated that only members of the 'Finance' group can access resources in the 'finance-project' during business hours (9 AM - 6 PM). Additionally, a new policy requires blocking all members of the 'contractors' group from accessing the same project, regardless of conditions. How should you configure IAM to meet these requirements?

  1. A

    Create an IAM policy with a condition restricting access to the 'finance-project' to the 'Finance' group between 9 AM and 6 PM.

  2. B

    Set up an IAM deny policy to explicitly block access to the 'finance-project' for the 'contractors' group.

  3. C

    Add the 'Finance' group as a member of the 'roles/editor' role without any conditions on the 'finance-project'.

  4. D

    Configure an IAM policy condition to deny access to the 'contractors' group only outside business hours (9 AM - 6 PM).

  5. E

    Create an IAM allow policy with a condition granting access to all users during business hours (9 AM - 6 PM).

Show answer and explanation

Correct answers: A, B

Explanation

To meet the requirements, you need to configure IAM to allow access to the 'Finance' group for the 'finance-project' during business hours using IAM conditions. Additionally, to block the 'contractors' group from accessing the project entirely, you should use an IAM deny policy, as deny policies override allow policies and are unconditional. Both configurations together fulfill the security team's requirements.

  • A. Correct.

    Correct: This ensures that only members of the 'Finance' group can access the 'finance-project' during business hours (9 AM - 6 PM) by using IAM conditions for time-based access control.

  • B. Correct.

    Correct: An IAM deny policy explicitly blocks access to the 'contractors' group, ensuring no access is granted under any circumstance.

  • C. Incorrect.

    Incorrect: Granting the 'roles/editor' role without conditions would violate the requirement to restrict access to business hours and limit it to the 'Finance' group.

  • D. Incorrect.

    Incorrect: Denying access to the 'contractors' group only outside business hours does not meet the requirement to block them entirely, irrespective of time.

  • E. Incorrect.

    Incorrect: Granting access to all users during business hours would contradict the requirement to restrict access to only the 'Finance' group.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam