Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 171 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 171

Select 3Google Cloud Platform

Your organization is rapidly expanding and managing hundreds of Google Cloud projects under various departments. To maintain consistent security policies and resource organization, you need to set up a scalable structure for managing folders and projects. Which of the following actions should you take to achieve this goal?

  1. A

    Use an organization node to centrally manage folders and projects.

  2. B

    Apply Identity and Access Management (IAM) policies at the folder level to inherit permissions to child projects.

  3. C

    Directly assign IAM roles to individual resources (e.g., Compute Engine instances) in each project for better granularity.

  4. D

    Use labels on projects to group them logically and enforce security policies.

  5. E

    Set up automated folder and project creation using Deployment Manager or Terraform.

Show answer and explanation

Correct answers: A, B, E

Explanation

To manage folders and projects at scale, it is essential to use a structured approach leveraging the organization node, IAM policies at a higher hierarchy level (like folders), and automation tools for consistent and scalable resource creation. Directly assigning IAM roles to individual resources is not scalable, and labels are not a substitute for hierarchical resource management or policy enforcement.

  • A. Correct.

    Correct. The organization node is the root node of the Google Cloud resource hierarchy. It allows for centralized management of folders and projects, ensuring consistent security and governance policies.

  • B. Correct.

    Correct. IAM policies applied at the folder level automatically propagate to all child projects and resources, simplifying permission management and ensuring consistency.

  • C. Incorrect.

    Incorrect. While directly assigning IAM roles to individual resources offers granularity, it is not scalable or recommended for managing permissions across hundreds of projects.

  • D. Incorrect.

    Incorrect. Labels are useful for organizing and filtering resources, but they do not enforce security policies or manage the resource hierarchy.

  • E. Correct.

    Correct. Using infrastructure-as-code tools like Deployment Manager or Terraform helps automate resource creation at scale with predefined policies and configurations.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam