Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 154 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 154

Single answerGoogle Cloud Platform

Your organization uses Google Cloud and needs to manage permissions for a team of developers who work on a specific project. To simplify access control, you decide to use Google Groups. How should you configure permissions to ensure the developers have the necessary access while maintaining security best practices?

  1. A

    Assign the required IAM roles directly to each individual developer.

  2. B

    Create a Google Group for the developers, and assign the required IAM roles to the group at the project level.

  3. C

    Create a Google Group for the developers, and assign the required IAM roles to the group at the resource level (e.g., specific Compute Engine instances).

  4. D

    Assign the required IAM roles to the Google Group at the organizational level to ensure all developers have access to all projects.

Show answer and explanation

Correct answer: B

Explanation

Using Google Groups to manage permissions is a best practice in Google Cloud. By assigning IAM roles to a group at the project level, you can ensure that all developers in the group have the necessary access to the project resources. This approach is easier to manage, scalable, and aligns with the principle of least privilege, as permissions are scoped to the project rather than the organization or individual resources.

  • A. Incorrect.

    Assigning IAM roles directly to individuals increases complexity and is against best practices for managing permissions at scale. It becomes harder to audit and manage permissions as team members change.

  • B. Correct.

    This is the correct approach. Assigning IAM roles to a Google Group at the project level simplifies permission management. Developers inherit the permissions from the group, and access can be managed by adding or removing them from the group.

  • C. Incorrect.

    While assigning IAM roles at the resource level can work, it is not recommended in this scenario because it creates unnecessary complexity. Managing permissions at the resource level is typically reserved for use cases where fine-grained control is needed.

  • D. Incorrect.

    Assigning IAM roles at the organizational level would give the developers access to all projects, violating the principle of least privilege. This approach grants excessive permissions and poses a security risk.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam