Professional Cloud DevOps Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise organization manages multi-tier application environments across development, staging, and production in Google Cloud. The DevOps and security teams must implement a robust, auditable CI/CD workflow to manage environment-specific IAM policies according to the principle of least privilege.
The proposed process must satisfy the following criteria:
Which combination of Google Cloud services and practices should the team implement?
Execute gcloud CLI scripts in deployment pipelines to apply IAM policies using the read-modify-write pattern, manage role recommendations through Event Threat Detection, and export Cloud SQL audit logs to track policy changes.
Configure exponential backoff retries with jitter to handle HTTP 409 ABORTED concurrency errors during manual Cloud Console updates, and utilize Data Access audit logs to monitor permission grants.
Manage IAM policies as code in a version-controlled repository, analyze over-privileged bindings with IAM Recommender, validate proposed policy changes before deployment using Policy Simulator, and capture all administrative changes via centralized IAM Admin Activity audit logs.
Require all automated CI/CD deployment service accounts to request elevated access through Privileged Access Manager (PAM), trigger Policy Troubleshooter on pull requests to auto-merge changes, and record changes using IAM System Event audit logs.
Execute gcloud CLI scripts in deployment pipelines to apply IAM policies using the read-modify-write pattern, manage role recommendations through Event Threat Detection, and export Cloud SQL audit logs to track policy changes.
Configure exponential backoff retries with jitter to handle HTTP 409 ABORTED concurrency errors during manual Cloud Console updates, and utilize Data Access audit logs to monitor permission grants.
Manage IAM policies as code in a version-controlled repository, analyze over-privileged bindings with IAM Recommender, validate proposed policy changes before deployment using Policy Simulator, and capture all administrative changes via centralized IAM Admin Activity audit logs.
This solution establishes a declarative GitOps workflow for managing IAM policies as code across all environment tiers. It integrates IAM Recommender for continuous least-privilege analysis, Policy Simulator (part of Policy Intelligence) to test proposed access changes prior to production deployment, and Cloud Audit Logs (specifically IAM Admin Activity audit logs) routed to a centralized log bucket for security compliance.
Alternative approaches rely on reactive troubleshooting or manual verification, which either introduce severe risk of production outages or fail to enforce least-privilege systematically. Combining IAM Recommender, Policy Simulator, and IAM Admin Activity audit logs provides an end-to-end preventative and detective security pipeline natively integrated with Google Cloud.
Require all automated CI/CD deployment service accounts to request elevated access through Privileged Access Manager (PAM), trigger Policy Troubleshooter on pull requests to auto-merge changes, and record changes using IAM System Event audit logs.