Professional Cloud DevOps Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
Your company organizes its Google Cloud resources using a multi-layer hierarchy where projects are grouped under department folders within an organization resource. You need to delegate access administration to the team leads of the Engineering department while adhering to the principle of least privilege.
The requirements are:
Engineering folder, with permissions automatically inheriting down to all child folders and projects.What should you do?
Create a Google Group for the Engineering team leads and grant the Folder IAM Admin role (roles/resourcemanager.folderIamAdmin) to the group on the Engineering folder.
Create a Google Group for the Engineering team leads and grant the Owner role (roles/owner) to the group on the Engineering folder.
Create a custom IAM role containing only the resourcemanager.projects.setIamPolicy permission and bind it to individual team leads across each project individually.
Assign the Organization Administrator role (roles/resourcemanager.organizationAdmin) directly to individual team lead user accounts on the organization resource.
Create a Google Group for the Engineering team leads and grant the Folder IAM Admin role (roles/resourcemanager.folderIamAdmin) to the group on the Engineering folder.
The Folder IAM Admin (roles/resourcemanager.folderIamAdmin) predefined role provides specific administrative permissions to administer IAM policies on folders without bundling broader data plane or general resource administration privileges.
roles/resourcemanager.folderIamAdmin on the Engineering folder allows leads to modify allow policies across the folder and its descendant resources through hierarchical policy inheritance.Using the predefined Folder IAM Admin role bound to a Google Group at the folder level fulfills the exact functional requirement of delegating IAM policy management while strictly enforcing least privilege and minimizing management overhead.
Create a Google Group for the Engineering team leads and grant the Owner role (roles/owner) to the group on the Engineering folder.
Create a custom IAM role containing only the resourcemanager.projects.setIamPolicy permission and bind it to individual team leads across each project individually.
Assign the Organization Administrator role (roles/resourcemanager.organizationAdmin) directly to individual team lead user accounts on the organization resource.