Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise organization manages microservices across hundreds of projects grouped under environment-specific folders in Google Cloud. The security team needs to configure IAM access according to the principle of least privilege for two distinct teams:
Which IAM role and resource hierarchy binding strategy should the security engineer implement?
Grant the SRE team Google Group the App Management Viewer role (roles/apphub.appManagementViewer) on the app-enabled folder, and grant each development team Google Group the Cloud Hub Operator role (roles/cloudhub.operator) on their respective projects.
Grant the SRE team Google Group the Cloud Hub Operator role (roles/cloudhub.operator) on the app-enabled folder, and grant individual developer accounts the App Management Viewer role (roles/apphub.appManagementViewer) on their respective projects.
Grant the SRE team Google Group the App Management Viewer role (roles/apphub.appManagementViewer) at the organization level, and grant development team Google Groups the Cloud Hub Operator role (roles/cloudhub.operator) on the parent folder.
Grant the SRE team Google Group the Cloud Hub Operator role (roles/cloudhub.operator) at the organization level, and grant development team Google Groups the App Management Viewer role (roles/apphub.appManagementViewer) on the parent folder.
Grant the SRE team Google Group the App Management Viewer role (roles/apphub.appManagementViewer) on the app-enabled folder, and grant each development team Google Group the Cloud Hub Operator role (roles/cloudhub.operator) on their respective projects.
This solution assigns predefined IAM roles to managed Google Groups at appropriate levels of the Google Cloud resource hierarchy, pairing the App Management Viewer (roles/apphub.appManagementViewer) role at the folder level with the Cloud Hub Operator (roles/cloudhub.operator) role at individual project levels.
roles/apphub.appManagementViewer on an app-enabled folder grants Site Reliability Engineers view permissions across all registered applications and components aggregated under that folder.roles/cloudhub.operator on specific target projects ensures developer access is confined strictly to the operational boundaries of their designated project workloads without exposing surrounding folder-level application architectures.Predefined Cloud Hub and App Hub roles are purpose-built for this exact architectural separation: roles/apphub.appManagementViewer provides application-level monitoring across folders, while roles/cloudhub.operator provides project-level metric and telemetry viewing.
Grant the SRE team Google Group the Cloud Hub Operator role (roles/cloudhub.operator) on the app-enabled folder, and grant individual developer accounts the App Management Viewer role (roles/apphub.appManagementViewer) on their respective projects.
Grant the SRE team Google Group the App Management Viewer role (roles/apphub.appManagementViewer) at the organization level, and grant development team Google Groups the Cloud Hub Operator role (roles/cloudhub.operator) on the parent folder.
Grant the SRE team Google Group the Cloud Hub Operator role (roles/cloudhub.operator) at the organization level, and grant development team Google Groups the App Management Viewer role (roles/apphub.appManagementViewer) on the parent folder.