Your company is moving workloads to Google Cloud. The operations group needs permission to start and stop Compute Engine instances and to view Cloud Logging entries. The security team insists that the granted role must not include permissions for unrelated services, and that any new relevant permissions should be added automatically by Google. Which IAM role approach should you take?
Create and assign a single custom role that lists only the start/stop instance and logging read permissions you need.
Grant the Service Account User role so team members can act as the default Compute Engine service account.
Grant the team Google-managed predefined roles that cover Compute Engine instance administration and log viewing.
Grant the basic Editor role at the project level so all required permissions are inherited.
Google-managed predefined roles such as roles/compute.instanceAdmin.v1 and roles/logging.viewer are maintained by Google and automatically receive any new permissions relevant to their services. They restrict access to Compute Engine instance administration and log viewing without granting broader project-wide privileges, meeting least-privilege and maintenance requirements.
Granting the basic Editor role would violate least privilege because it includes thousands of permissions across many services, even though it does not allow changing IAM policies. Creating a custom role would avoid excess permissions but would require manual updates whenever Google adds new permissions to Compute Engine or Cloud Logging. The Service Account User role only lets principals act as (or attach) a service account; it does not grant the ability to start instances or view logs.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are Google-managed predefined roles?
Open an interactive chat with Bash
How does a custom role differ from predefined roles?
Open an interactive chat with Bash
Why is the least privilege principle important in IAM role assignment?
Open an interactive chat with Bash
What is the purpose of Google-managed predefined IAM roles?
Open an interactive chat with Bash
What does 'least privilege' mean in IAM roles?
Open an interactive chat with Bash
How do custom IAM roles differ from predefined IAM roles?
Open an interactive chat with Bash
GCP Associate Cloud Engineer
Configuring access and security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .