Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
A multinational financial services enterprise is preparing for an annual regulatory compliance audit. The security engineering team needs to determine every principal—including individual users, nested Google Groups, and service accounts—that possesses effective storage.objects.get or storage.objects.setIamPolicy permissions on specific sensitive Cloud Storage buckets across multiple production projects.
Access to these buckets may be granted directly at the bucket level, inherited from parent folders or the organization root, or granted indirectly through custom IAM roles and group memberships.
Which approach should the security engineering team use to evaluate these effective access paths with minimal operational overhead?
Policy Analyzer is a core component of Google Cloud's Policy Intelligence suite (integrated with Cloud Asset Inventory) designed to evaluate and understand effective IAM permissions across complex resource hierarchies. It answers critical security questions such as "Who has what access to which resources?" by performing deep analysis of IAM policies, role definitions, and group memberships.
storage.objects.get and storage.objects.setIamPolicy), and maps every individual principal to the exact authorization path.Policy Analyzer natively computes the transitive closure of all IAM policies, custom role definitions, and Google Group hierarchies across the entire resource tree, delivering complete visibility into effective access in a single query.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.