Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 133 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 133

Single answerGoogle Cloud Platform

Your organization is migrating to Google Cloud and has strict security policies requiring the enforcement of the principle of least privilege. You have been tasked with granting access to a team of developers who will manage resources only within a single project. The developers need permissions to create, update, and delete Compute Engine instances, but should not have access to other resources or projects. How should you configure access to meet the requirements?

  1. A

    Assign the 'Compute Admin' role at the organization level to the developers.

  2. B

    Assign the 'Compute Admin' role at the project level to the developers.

  3. C

    Assign the 'Editor' role at the project level to the developers.

  4. D

    Create a custom role with permissions specific to managing Compute Engine instances and assign it at the project level to the developers.

Show answer and explanation

Correct answer: D

Explanation

The principle of least privilege dictates that users should only be granted the minimum permissions necessary to perform their job functions. While predefined roles like 'Compute Admin' or 'Editor' might meet functional requirements, they often include more permissions than needed, which increases the security risk. By creating a custom role with only the required permissions for managing Compute Engine instances and assigning it at the project level, you ensure both functional and security requirements are met.

  • A. Incorrect.

    Assigning the 'Compute Admin' role at the organization level violates the principle of least privilege because it grants access across all projects and resources in the organization, far exceeding the scope required for the developers.

  • B. Incorrect.

    Assigning the 'Compute Admin' role at the project level provides developers with permissions to manage Compute Engine within the project. However, this role may also include permissions that exceed the specific actions required, such as managing networking settings, which goes against the principle of least privilege.

  • C. Incorrect.

    Assigning the 'Editor' role at the project level grants broad permissions to manage all resources within the project, including storage, databases, and networking, which is unnecessary and violates the principle of least privilege.

  • D. Correct.

    Creating a custom role with the exact permissions required for managing Compute Engine instances ensures that developers only have the permissions necessary for their tasks. Assigning this role at the project level restricts their access to the specific project, aligning with the principle of least privilege.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam