Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 180 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 180

Single answerGoogle Cloud Platform

Your organization uses Google Cloud and has created a resource hierarchy with three levels: Organization > Folders > Projects. The security team needs to ensure that a specific IAM role granting read-only access to data is inherited by all resources under a 'Finance' folder, but no other departments. How can this be achieved?

  1. A

    Assign the IAM role at the Organization level and use conditional IAM policies to restrict it to the 'Finance' folder.

  2. B

    Assign the IAM role at the 'Finance' folder level, ensuring it automatically propagates to all resources under the folder.

  3. C

    Assign the IAM role to each individual project within the 'Finance' folder to avoid affecting resources outside the folder.

  4. D

    Assign the IAM role at the 'Finance' folder level and disable permissions inheritance for other folders.

Show answer and explanation

Correct answer: B

Explanation

To effectively grant read-only access to all resources under the 'Finance' folder without affecting other departments, assigning the IAM role at the 'Finance' folder level is the best approach. This leverages the resource hierarchy's permissions inheritance, ensuring that all projects and resources within the folder automatically inherit the role.

  • A. Incorrect.

    IAM roles assigned at the Organization level apply to all resources in the hierarchy unless further restrictions are applied. Conditional IAM policies cannot selectively restrict inheritance to a specific folder.

  • B. Correct.

    Assigning the IAM role at the 'Finance' folder level ensures that the role is inherited by all resources under the 'Finance' folder, providing a scalable and efficient solution.

  • C. Incorrect.

    Assigning the IAM role individually to each project within the 'Finance' folder would work but is not scalable or efficient, especially as new projects are added.

  • D. Incorrect.

    Permissions inheritance cannot be selectively disabled for specific folders in the hierarchy. IAM roles are inherited by default unless explicitly overridden at a lower level.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam