A developer needs permission to start and stop existing Compute Engine VMs and to read Cloud Monitoring metrics for those VMs. The compute.instanceAdmin.v1 predefined role lets the user create and delete instances, and the Editor basic role grants many unrelated permissions. What kind of IAM role should you grant to satisfy least-privilege requirements?
Grant the basic Editor role at the project level.
Create a custom role that includes only the required start, stop, and monitoring permissions.
Grant the predefined compute.instanceAdmin.v1 role at the project level.
Combine the Viewer basic role with the predefined Monitoring Viewer role.
Neither of the predefined options meets the principle of least privilege. compute.instanceAdmin.v1 allows instance creation and deletion, while the Editor basic role is even broader. By creating a custom role that contains only compute.instances.start, compute.instances.stop, and monitoring.timeSeries.list (plus any other strictly required permissions), you restrict the user to the exact actions needed and avoid unnecessary access.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the principle of least privilege in IAM?
Open an interactive chat with Bash
How are predefined roles different from custom roles in GCP IAM?
Open an interactive chat with Bash
What permissions are needed to view Cloud Monitoring metrics?
Open an interactive chat with Bash
What is the principle of least privilege in IAM roles?
Open an interactive chat with Bash
What are custom IAM roles in GCP and how are they created?
Open an interactive chat with Bash
What does the predefined compute.instanceAdmin.v1 role include?
Open an interactive chat with Bash
GCP Associate Cloud Engineer
Configuring access and security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .