Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise organization manages a Google Cloud resource hierarchy consisting of an Organization node, several environment folders (Production, Staging, Development), and dozens of child projects. The security team wants to implement tag-based access control (TBAC) with IAM Conditions to grant the Cloud Operations team (cloud-ops@example.com) administrative permissions across virtual machines under the following requirements:
roles/compute.admin dynamically only on resources evaluated with the environment: production tag value.Production folder must automatically inherit production tag enforcement without requiring per-project configuration, while allowing descendant resources to override the tag value when necessary.Which strategy should the security engineer implement?
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.