Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise manages multiple database workloads across several projects located inside a single folder named Application-Services. The security team needs to grant members of the database administration team permissions to inspect and configure Cloud SQL instances across all current and future projects in this folder.
The access control architecture must satisfy the following constraints:
What should the security engineer do to enforce the principle of least privilege?
IAM Custom Roles allow security administrators to bundle granular, discrete permissions tailored specifically to workload responsibilities when predefined or basic roles do not meet the principle of least privilege. Defining custom roles at the folder level ensures that the role definition is inherited and available across all underlying descendant projects within that branch of the resource hierarchy.
cloudsql.instances.delete.cloudsql.instances.get and cloudsql.instances.list satisfies the prerequisite console dependency, allowing users to view and select instances in the Google Cloud console UI without error.Application-Services folder enforces policy consistency across all existing and newly created descendant projects automatically.setIamPolicy).Creating a targeted custom role at the folder hierarchy level directly achieves the balance between administrative functionality and strict least-privilege governance.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.