Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 136 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 136

Single answerGoogle Cloud Platform

Your organization uses Google Cloud, and you have been tasked with setting up access control for a project. The project contains sensitive financial data, and only a small team of accountants should have access to it. The organization has hundreds of other users who should not have any access to this project. Following the principle of least privilege, how should you configure access control for this project?

  1. A

    Grant the 'Viewer' role to the accountants at the organization level and restrict access for others using deny policies.

  2. B

    Grant the 'Viewer' role to the accountants at the project level and ensure no other roles are assigned to this project.

  3. C

    Grant the 'Owner' role to the accountants at the folder level that contains the project.

  4. D

    Grant the 'Viewer' role to the accountants at the project level and ensure IAM inheritance does not provide broader access from the folder or organization level.

Show answer and explanation

Correct answer: D

Explanation

The principle of least privilege requires granting users the minimal set of permissions necessary to perform their tasks. By assigning the 'Viewer' role at the project level, you restrict access to only the accountants who need it, limiting exposure to sensitive financial data. Verifying IAM inheritance ensures no broader permissions from the folder or organization levels inadvertently grant access to other users.

  • A. Incorrect.

    Granting the 'Viewer' role at the organization level violates the principle of least privilege because it gives the accountants access to all projects and resources in the organization, not just the financial data project.

  • B. Incorrect.

    This is partially correct but incomplete. While granting the 'Viewer' role to accountants at the project level aligns with the principle of least privilege, failing to verify IAM inheritance could still unintentionally grant broader access to the project.

  • C. Incorrect.

    Granting the 'Owner' role at the folder level is a poor choice because it not only violates the principle of least privilege but also provides excessive permissions (e.g., full administrative rights) that are unnecessary for the accountants.

  • D. Correct.

    This is the correct answer. Granting the 'Viewer' role at the project level ensures that access is limited to only the necessary project. Additionally, checking IAM inheritance ensures that no unintended permissions cascade from higher levels (folder or organization).

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam