Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise manages multiple database workloads across several projects located inside a single folder named Application-Services. The security team needs to grant members of the database administration team permissions to inspect and configure Cloud SQL instances across all current and future projects in this folder.
The access control architecture must satisfy the following constraints:
What should the security engineer do to enforce the principle of least privilege?
Grant the basic roles/editor role to the database administration group on each individual project under the Application-Services folder.
Create a custom IAM role at the organization level containing only cloudsql.instances.get, and bind it to the database administration group on the Application-Services folder.
Create a custom IAM role at the folder level that includes the required Cloud SQL permissions—including both cloudsql.instances.get and cloudsql.instances.list—and bind this role to the database administration group on the Application-Services folder.
Grant the predefined roles/cloudsql.admin role to the database administration group at the Application-Services folder level.
Grant the basic roles/editor role to the database administration group on each individual project under the Application-Services folder.
Create a custom IAM role at the organization level containing only cloudsql.instances.get, and bind it to the database administration group on the Application-Services folder.
Create a custom IAM role at the folder level that includes the required Cloud SQL permissions—including both cloudsql.instances.get and cloudsql.instances.list—and bind this role to the database administration group on the Application-Services folder.
IAM Custom Roles allow security administrators to bundle granular, discrete permissions tailored specifically to workload responsibilities when predefined or basic roles do not meet the principle of least privilege. Defining custom roles at the folder level ensures that the role definition is inherited and available across all underlying descendant projects within that branch of the resource hierarchy.
cloudsql.instances.delete.cloudsql.instances.get and cloudsql.instances.list satisfies the prerequisite console dependency, allowing users to view and select instances in the Google Cloud console UI without error.Application-Services folder enforces policy consistency across all existing and newly created descendant projects automatically.setIamPolicy).Creating a targeted custom role at the folder hierarchy level directly achieves the balance between administrative functionality and strict least-privilege governance.
Grant the predefined roles/cloudsql.admin role to the database administration group at the Application-Services folder level.