Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise organizes its Google Cloud resources under an Engineering parent folder, which contains two subfolders: Development and Production. A security auditor discovers that the group dev-team@example.com is currently bound to the Compute Instance Admin role (roles/compute.instanceAdmin) directly on the Engineering folder.
The security team must enforce the following access requirements:
Development folder.roles/compute.viewer) for Compute Engine instances within projects located in the Production folder.Which architectural change should the security team implement to satisfy these access requirements?
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.