Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise security team is establishing authorization guardrails across Google Cloud resource hierarchies. The team needs to enforce the following access requirements on a folder named Production-Workloads:
developers@example.com from creating and deleting service account keys across all current and future projects in the folder, even if they hold broad project-level Owner or Editor IAM roles.breakglass-ops@example.com (whose members are also in developers@example.com) to retain full permissions to create and delete service account keys within these projects.Which configuration should the security team implement to satisfy these requirements?
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.