Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A security engineer is evaluating IAM Role Recommendations in Google Cloud to transition an automated data processing service account away from the overly broad roles/editor basic role. While analyzing the recommendation in the Google Cloud console, the engineer notes the following details:
roles/editor with a narrower predefined role.What should the security engineer consider before applying this role recommendation to ensure production operations are not disrupted?
Reject the recommendation immediately because blue machine learning-flagged permissions indicate high-risk lateral movement vulnerabilities.
Ensure that the service account is assigned the Role Administrator role (roles/iam.roleAdmin) to allow it to self-apply the recommended custom role at runtime.
Assume that the IAM Recommender automatically accounts for Cloud Storage ACLs and GKE RBAC bindings when calculating the suggested role replacement.
Manually verify that the workload's operations do not depend on Cloud Storage ACLs or GKE RBAC, and understand that blue machine learning-flagged permissions will be retained in the recommended role based on predicted future need.
Reject the recommendation immediately because blue machine learning-flagged permissions indicate high-risk lateral movement vulnerabilities.
Ensure that the service account is assigned the Role Administrator role (roles/iam.roleAdmin) to allow it to self-apply the recommended custom role at runtime.
Assume that the IAM Recommender automatically accounts for Cloud Storage ACLs and GKE RBAC bindings when calculating the suggested role replacement.
Manually verify that the workload's operations do not depend on Cloud Storage ACLs or GKE RBAC, and understand that blue machine learning-flagged permissions will be retained in the recommended role based on predicted future need.
IAM Recommender is a Policy Intelligence tool that compares granted permissions against exercised permissions over an observation period (by default, 90 days). It provides role recommendations and policy insights (google.iam.policy.Insight) to help security teams safely transition principals from overly permissive roles (such as basic roles like roles/editor or roles/owner) to tightly scoped predefined or custom roles.
When analyzing the impact of a role replacement in the Google Cloud console:
roles/editor will not break external authorizations.This approach ensures that all dependencies—both within IAM and in external systems like Cloud Storage ACLs and GKE RBAC—are fully validated before applying the recommendation.