Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise organization manages microservices across hundreds of projects grouped under environment-specific folders in Google Cloud. The security team needs to configure IAM access according to the principle of least privilege for two distinct teams:
Which IAM role and resource hierarchy binding strategy should the security engineer implement?
This solution assigns predefined IAM roles to managed Google Groups at appropriate levels of the Google Cloud resource hierarchy, pairing the App Management Viewer (roles/apphub.appManagementViewer) role at the folder level with the Cloud Hub Operator (roles/cloudhub.operator) role at individual project levels.
roles/apphub.appManagementViewer on an app-enabled folder grants Site Reliability Engineers view permissions across all registered applications and components aggregated under that folder.roles/cloudhub.operator on specific target projects ensures developer access is confined strictly to the operational boundaries of their designated project workloads without exposing surrounding folder-level application architectures.Predefined Cloud Hub and App Hub roles are purpose-built for this exact architectural separation: roles/apphub.appManagementViewer provides application-level monitoring across folders, while roles/cloudhub.operator provides project-level metric and telemetry viewing.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.