Intrigued by the art of cloud architecture? Discover how to design, develop, and manage robust, secure, scalable, and dynamic solutions on Google Cloud as you prepare for the Professional Cloud Architect exam!
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise organization is structuring its Google Cloud resource hierarchy to maintain a strict separation of duties across departments. The company must satisfy the following security and governance requirements:
Which resource hierarchy and access management architecture should the organization implement?
Define separate departmental folders beneath the Organization resource; assign the Security team the Organization Policy Administrator and Security Reviewer roles at the Organization level, and assign Development teams project-level resource admin roles within their specific departmental folders.
Assign the Central Security team the Owner role at the Organization level, and assign Development teams the Editor role on the Organization node so both teams inherit necessary permissions across all folders.
Place all departmental projects into a single flat hierarchy directly under the Organization node, and assign the Central Security team individual project-level Editor roles while assigning developers Organization-level Viewer roles.
Configure a single Shared folder containing all resources, grant the Central Security team Organization Admin, and configure service accounts with local project Owner roles that developers impersonate for all tasks.
Define separate departmental folders beneath the Organization resource; assign the Security team the Organization Policy Administrator and Security Reviewer roles at the Organization level, and assign Development teams project-level resource admin roles within their specific departmental folders.
This architecture establishes a structured Google Cloud resource hierarchy utilizing top-level folders mapped by department, combined with distinct Identity and Access Management (IAM) role assignments at precise hierarchy tiers to maintain separation of duties.
roles/orgpolicy.policyAdmin and roles/iam.securityReviewer (or roles/viewer) at the Organization node allows central administration of guardrails and read-only visibility across every child folder and project without granting workload deployment or data modification permissions.roles/compute.instanceAdmin.v1 or roles/editor) scoped strictly to their respective departmental folders ensures development teams cannot affect neighboring business units.This model follows the principle of least privilege and strict segregation of duties. High-level access is limited to auditing and policy enforcement, while resource-creation privileges remain confined to leaf or departmental scopes.
Assign the Central Security team the Owner role at the Organization level, and assign Development teams the Editor role on the Organization node so both teams inherit necessary permissions across all folders.
Place all departmental projects into a single flat hierarchy directly under the Organization node, and assign the Central Security team individual project-level Editor roles while assigning developers Organization-level Viewer roles.
Configure a single Shared folder containing all resources, grant the Central Security team Organization Admin, and configure service accounts with local project Owner roles that developers impersonate for all tasks.