Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A site reliability engineer (SRE) is blocked by a permission error when attempting to perform an emergency deployment in a production Google Cloud project. The SRE sends an access request via the error message dialog, notifying your security operations team.
Upon reviewing the request details within the Policy Troubleshooter remediation summary, you confirm that the access failure is caused by an allow policy missing the required permissions. Your organization enforces a strict enterprise security compliance baseline requiring least privilege and just-in-time (JIT) access, which prohibits granting permanent elevated privileges in production environments.
Which action should you take within the remediation workflow to resolve this access issue in accordance with organizational policy?
Update the organization's IAM deny policy by adding the SRE's principal identifier as an exception principal on the blocked permission.
Navigate to the Remediate allow policy view in Policy Troubleshooter, select Grant role, and apply a CEL condition using request.time to enforce an expiration timestamp on the permanent role binding.
Use Policy Analyzer to query all effective allow policies, identify an existing administrative group containing the missing permissions, and permanently add the SRE to that Google Group.
Navigate to the Remediate allow policy view in Policy Troubleshooter, select Grant temporary access, configure a Privileged Access Manager (PAM) entitlement with a defined maximum grant duration, and approve the user's grant request.
Update the organization's IAM deny policy by adding the SRE's principal identifier as an exception principal on the blocked permission.
Navigate to the Remediate allow policy view in Policy Troubleshooter, select Grant role, and apply a CEL condition using request.time to enforce an expiration timestamp on the permanent role binding.
Use Policy Analyzer to query all effective allow policies, identify an existing administrative group containing the missing permissions, and permanently add the SRE to that Google Group.
Navigate to the Remediate allow policy view in Policy Troubleshooter, select Grant temporary access, configure a Privileged Access Manager (PAM) entitlement with a defined maximum grant duration, and approve the user's grant request.
Policy Troubleshooter provides an integrated remediation workflow that enables security administrators to diagnose access denials and take immediate action. When diagnosing permission errors caused by allow policies, the console offers the option to either grant a permanent role or create a Privileged Access Manager (PAM) entitlement for temporary, just-in-time (JIT) privilege elevation.
Granting temporary access through Privileged Access Manager fulfills the emergency access need while strictly adhering to enterprise security baselines that ban permanent standing privileges in production environments.