Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 134 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 134

Select 3Google Cloud Platform

Your company uses Google Cloud and manages multiple projects, each belonging to different departments such as Finance, Marketing, and Engineering. The Security team has identified that some users have overly broad permissions at the organization level, which violates the principle of least privilege. How should you redesign your access control strategy to adhere to the principle of least privilege while maintaining efficient management of permissions?

  1. A

    Assign roles to users at the organization level to simplify access management.

  2. B

    Define IAM policies at the folder level for each department to group related projects and assign roles specific to department needs.

  3. C

    Use predefined roles instead of overly permissive custom roles to align with job responsibilities.

  4. D

    Grant permissions at the project level only when specific users or groups require access to a particular project.

  5. E

    Use the Owner role at all levels to ensure all users can manage resources if needed.

Show answer and explanation

Correct answers: B, C, D

Explanation

To adhere to the principle of least privilege, you should avoid granting broad permissions at the organization level and instead define access control policies at more granular levels, such as folders and projects. Using predefined roles ensures permissions are aligned with job responsibilities, and granting access at the project level ensures users only have access to the resources they need. Avoid overly permissive roles, such as Owner, as they do not adhere to the principle of least privilege.

  • A. Incorrect.

    Assigning roles at the organization level violates the principle of least privilege since it can grant users access to resources they do not need. This approach is not recommended.

  • B. Correct.

    Defining IAM policies at the folder level allows you to group related projects under a folder and assign roles specific to the needs of each department. This adheres to the principle of least privilege.

  • C. Correct.

    Predefined roles are designed with specific job functions in mind and avoid granting excessive permissions. They are a better choice than overly permissive custom roles.

  • D. Correct.

    Granting permissions at the project level ensures that access is restricted to the specific resources users need, which aligns with the principle of least privilege.

  • E. Incorrect.

    The Owner role grants full administrative access, which is overly permissive and violates the principle of least privilege. It should not be used as a general practice.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam