Professional Cloud DevOps Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
A DevOps team is managing access across a multi-tier Google Cloud resource hierarchy. A developer reports that they are unable to delete objects from a specific Cloud Storage bucket in a production project, despite having the Storage Object Admin (roles/storage.objectAdmin) role directly granted to their identity on that bucket.
During your investigation of the resource hierarchy, you identify the following IAM configurations:
storage.objects.delete to all members of the developer group.roles/storage.objectViewer) role.roles/storage.objectAdmin) role.How does Google Cloud IAM evaluate these cumulative policies to determine the developer's effective permissions on the bucket?
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.