Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise has activated Security Command Center (SCC) at the organization level across their Google Cloud environment. A security engineer needs to configure granular Identity and Access Management (IAM) permissions to fulfill two specific operational requirements:
Folder-BU1), without viewing attack paths or resources outside that folder.Which combination of IAM role bindings should the security engineer implement?
Grant roles/securitycenter.admin to the central SecOps audit team at the organization level, and grant roles/securitycenter.adminViewer to the divisional compliance team at the Folder-BU1 level.
Grant roles/securitycenter.findingsViewer and roles/securitycenter.assetsViewer to the central SecOps audit team at the organization level, and grant roles/securitycenter.findingsEditor to the divisional compliance team at the Folder-BU1 level.
Grant roles/securitycenter.adminViewer to the central SecOps audit team at the organization level, and grant roles/securitycenter.assetsViewer and roles/securitycenter.findingsViewer to the divisional compliance team at the Folder-BU1 level.
Grant roles/securitycentermanagement.admin to the central SecOps audit team at the organization level, and grant roles/securitycenter.settingsViewer to the divisional compliance team at the Folder-BU1 level.
Grant roles/securitycenter.admin to the central SecOps audit team at the organization level, and grant roles/securitycenter.adminViewer to the divisional compliance team at the Folder-BU1 level.
Grant roles/securitycenter.findingsViewer and roles/securitycenter.assetsViewer to the central SecOps audit team at the organization level, and grant roles/securitycenter.findingsEditor to the divisional compliance team at the Folder-BU1 level.
Grant roles/securitycenter.adminViewer to the central SecOps audit team at the organization level, and grant roles/securitycenter.assetsViewer and roles/securitycenter.findingsViewer to the divisional compliance team at the Folder-BU1 level.
Google Cloud Security Command Center (SCC) uses specialized Identity and Access Management (IAM) predefined roles that align with the resource hierarchy (Organization, Folder, and Project) to enforce least-privilege visibility and administration.
roles/securitycenter.adminViewer) role at the organization level provides comprehensive, read-only permissions across the entire organization. It allows the team to inspect all discovered assets, security findings, and attack exposure paths in the Security Command Center console without granting permissions to change configurations, mute findings, or modify detection services.roles/securitycenter.assetsViewer) and Security Center Findings Viewer (roles/securitycenter.findingsViewer) roles specifically at the Folder-BU1 level scopes asset and finding visibility strictly to resources nested under that specific folder. It prevents the divisional compliance team from seeing findings, assets, or attack paths elsewhere in the organization hierarchy.securitycenter.*.update or securitycenter.*.create), preventing accidental or malicious modification of security baselines.This configuration cleanly separates organization-wide administrative auditing from departmental finding reviews, strictly enforcing least privilege through native Google Cloud Resource Manager hierarchy boundaries.
Grant roles/securitycentermanagement.admin to the central SecOps audit team at the organization level, and grant roles/securitycenter.settingsViewer to the divisional compliance team at the Folder-BU1 level.