Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
A multinational financial services enterprise is preparing for an annual regulatory compliance audit. The security engineering team needs to determine every principalâincluding individual users, nested Google Groups, and service accountsâthat possesses effective storage.objects.get or storage.objects.setIamPolicy permissions on specific sensitive Cloud Storage buckets across multiple production projects.
Access to these buckets may be granted directly at the bucket level, inherited from parent folders or the organization root, or granted indirectly through custom IAM roles and group memberships.
Which approach should the security engineering team use to evaluate these effective access paths with minimal operational overhead?
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.