Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 150 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 150

Select 2Google Cloud Platform

Your organization is using Google Cloud IAM to manage permissions for multiple projects. The security team has decided to use Google Groups to simplify managing permissions across teams. How should you configure IAM permissions to ensure that all members of the 'DevOps' Google Group have consistent access to resources across all projects they work on, while adhering to the principle of least privilege?

  1. A

    Assign individual roles to each member of the 'DevOps' Google Group directly in IAM.

  2. B

    Assign IAM roles to the 'DevOps' Google Group at the project level for each project they need access to.

  3. C

    Grant the 'DevOps' Google Group the 'Owner' role at the organization level for simplicity.

  4. D

    Assign IAM roles to the 'DevOps' Google Group at the folder level if the projects are organized within a folder.

  5. E

    Create a custom role with all required permissions and assign it to the 'DevOps' Google Group at the organization level.

Show answer and explanation

Correct answers: B, D

Explanation

To manage permissions effectively using Google Groups, roles should be assigned to the group at the appropriate resource level (project or folder) to ensure access is granted only where needed. Assigning roles at the project level works well for project-specific access, while using the folder level simplifies management for multiple projects under a common folder. Both approaches adhere to the principle of least privilege, ensuring the group doesn’t have unnecessary access to unrelated resources.

  • A. Incorrect.

    Assigning roles to individual members directly violates the principle of using groups for centralized management. It makes tracking and changing permissions more complex.

  • B. Correct.

    Assigning IAM roles to the 'DevOps' Google Group at the project level ensures that access is limited to specific projects, adhering to the principle of least privilege. This is a recommended practice.

  • C. Incorrect.

    Granting the 'Owner' role at the organization level gives excessive permissions, which violates the principle of least privilege.

  • D. Correct.

    Assigning IAM roles to the 'DevOps' Google Group at the folder level is appropriate if the projects are organized within a folder. This approach simplifies management while adhering to the principle of least privilege.

  • E. Incorrect.

    Assigning a custom role at the organization level may simplify management, but it grants permissions across all resources in the organization, which may exceed what the 'DevOps' team requires.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam