Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 137 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 137

Single answerGoogle Cloud Platform

Your organization is adopting the principle of least privilege for managing access to Google Cloud resources. A new team of developers needs access to a specific folder containing several projects. The developers should only be able to create and manage resources within these projects, without granting permissions to others or modifying resource hierarchy. How should you configure their access to align with the principle of least privilege?

  1. A

    Grant the 'Owner' role at the folder level to the developers.

  2. B

    Grant the 'Editor' role at the folder level to the developers.

  3. C

    Grant the 'Editor' role at the project level for each project within the folder to the developers.

  4. D

    Grant custom roles with only the required permissions to create and manage resources at the project level to the developers.

Show answer and explanation

Correct answer: D

Explanation

The principle of least privilege dictates that users should only be granted the permissions necessary to perform their tasks. Assigning custom roles with only the permissions required to create and manage resources at the project level ensures that developers cannot perform actions outside their responsibilities, such as managing IAM policies or modifying folder-level resources. This minimizes security risks and adheres to best practices for access control.

  • A. Incorrect.

    Granting the 'Owner' role at the folder level violates the principle of least privilege as it provides excessive permissions, including the ability to modify IAM policies and resource hierarchy.

  • B. Incorrect.

    Granting the 'Editor' role at the folder level provides broad access to all projects within the folder, which is unnecessary and does not adhere to least privilege principles.

  • C. Incorrect.

    Granting the 'Editor' role at the project level is better than granting it at the folder level, but it still provides unnecessary permissions such as managing IAM policies. This does not fully align with the principle of least privilege.

  • D. Correct.

    Granting custom roles with only the required permissions to create and manage resources ensures the developers have the minimum access they need without over-provisioning, fully adhering to the principle of least privilege.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam