Intrigued by the art of cloud architecture? Discover how to design, develop, and manage robust, secure, scalable, and dynamic solutions on Google Cloud as you prepare for the Professional Cloud Architect exam!
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise organization is establishing a standardized self-service provisioning and access management workflow for engineering teams in Google Cloud. The cloud architecture team must implement an access lifecycle model that meets the following security and governance requirements:
roles/editor upon creation.Which combination of IAM and governance controls should you implement?
Utilize Cloud Identity Groups for Business collaboration groups for IAM role assignments, and delegate group creation and membership management directly to all developers without approval guardrails.
Assign IAM roles directly to individual developer accounts using IAM Conditions with scheduled expiration timestamps, while allowing default service account provisioning during project creation.
Grant standing primitive Owner roles to developers via a central infrastructure pipeline, and schedule automated nightly scripts to delete and recreate project IAM policies.
Manage access using workload-specific access groups integrated with a Just-In-Time (JIT) self-service tool with auto-expiring memberships, assign IAM roles to these groups, and enforce the constraints/iam.automaticIamGrantsForDefaultServiceAccounts organization policy constraint.
Utilize Cloud Identity Groups for Business collaboration groups for IAM role assignments, and delegate group creation and membership management directly to all developers without approval guardrails.
Assign IAM roles directly to individual developer accounts using IAM Conditions with scheduled expiration timestamps, while allowing default service account provisioning during project creation.
Grant standing primitive Owner roles to developers via a central infrastructure pipeline, and schedule automated nightly scripts to delete and recreate project IAM policies.
Manage access using workload-specific access groups integrated with a Just-In-Time (JIT) self-service tool with auto-expiring memberships, assign IAM roles to these groups, and enforce the constraints/iam.automaticIamGrantsForDefaultServiceAccounts organization policy constraint.
Workload-specific access groups and Just-In-Time (JIT) group management tools provide a scalable, self-service mechanism for governing permissions across Google Cloud resources. Instead of binding IAM roles directly to individual users, roles are assigned to dedicated access groups representing specific job functions. A self-service tool (such as JIT Groups) evaluates access requests, enforces justification and approval workflows, and automatically expires user memberships when the approved duration concludes.
iam.automaticIamGrantsForDefaultServiceAccounts organization policy constraint disables the automatic assignment of roles/editor when new services or projects are provisioned.Combining JIT-managed access groups with organization policy constraints establishes a secure, repeatable self-service model. It enforces least-privilege access during runtime and guarantees baseline guardrails are inherited by every newly provisioned project.