Intrigued by the art of cloud architecture? Discover how to design, develop, and manage robust, secure, scalable, and dynamic solutions on Google Cloud as you prepare for the Professional Cloud Architect exam!
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise is designing its Google Cloud resource hierarchy. The organization consists of multiple business units, including a Finance division that manages several sensitive workloads across multiple projects grouped under a Finance folder.
The cloud architecture must satisfy the following security and governance requirements:
Finance folder.Which combination of IAM and resource governance practices should the cloud architect recommend?
This approach combines group-based access control, the principle of least privilege, and specific predefined Resource Manager roles to govern a defined branch of the resource hierarchy. It also establishes distinct trust boundaries for applications using dedicated service accounts.
roles/resourcemanager.folderIamAdmin) role allows the designated security team to manage IAM allow policies across the folder and all its child projects. Crucially, unlike broad administrative roles, Folder IAM Admin does not grant direct read, write, or management access to data resources (such as Cloud Storage objects or Compute Engine instances).Finance folder through automatic policy inheritance.This solution provides the precise level of administrative authority requested without over-granting permissions or exposing data payloads, perfectly aligning with enterprise security architecture standards.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.