Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 132 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 132

Single answerGoogle Cloud Platform

You are designing access control policies for a company's Google Cloud environment. The company wants to ensure that access is granted following the principle of least privilege. A team of developers needs to manage Compute Engine instances within a specific project, but they should not have the ability to modify IAM policies or access resources in other projects. How should you configure access for the developers?

  1. A

    Assign the 'Owner' role to the developers at the project level.

  2. B

    Assign the 'Compute Admin' role to the developers at the project level.

  3. C

    Assign the 'Compute Viewer' role to the developers at the project level.

  4. D

    Assign the 'Compute Instance Admin (v1)' role to the developers at the project level.

Show answer and explanation

Correct answer: D

Explanation

The principle of least privilege states that users should only be granted the minimum permissions necessary to perform their job. By assigning the 'Compute Instance Admin (v1)' role to the developers at the project level, you ensure they can manage Compute Engine instances without granting broader permissions such as modifying IAM policies or managing unrelated resources. This configuration effectively balances access control and security.

  • A. Incorrect.

    The 'Owner' role grants full administrative access to the project, including the ability to manage IAM policies. This violates the principle of least privilege.

  • B. Incorrect.

    The 'Compute Admin' role grants broad permissions to manage all Compute Engine resources in the project, including creating and deleting instances, as well as managing networks and firewalls. This may exceed the necessary permissions needed by the developers.

  • C. Incorrect.

    The 'Compute Viewer' role only allows read-only access to Compute Engine resources, which is not sufficient for developers who need to manage instances.

  • D. Correct.

    The 'Compute Instance Admin (v1)' role allows users to create, modify, and delete Compute Engine instances without granting permissions to manage IAM policies or other unrelated resources. This aligns with the principle of least privilege.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam