Your company runs several Compute Engine VMs in the prod-vm project. The security team must let on-call SREs start or stop instances during incidents, but the SREs must not be able to create, delete, or modify any other resources. No existing predefined IAM role grants exactly this permission set. What is the most appropriate action to meet the requirement?
Create a custom IAM role containing only the start and stop instance permissions, then grant that role to the on-call SRE group on the project.
Create a service account with the required permissions and distribute its key to the on-call SREs for impersonation.
Grant the predefined role roles/compute.instanceAdmin.v1 to the on-call SRE group.
Grant the Project Editor role and add an organization policy that denies instance deletion.
A custom IAM role allows you to bundle only the required permissions-such as compute.instances.start and compute.instances.stop-and assign it to a principal at the project level. Predefined roles like roles/compute.instanceAdmin.v1 or the Project Editor role include additional permissions such as instance deletion that violate the security team's constraint. Sharing a service-account key is strongly discouraged because it bypasses least-privilege principles and creates key-management risks. An organization policy cannot selectively strip specific permissions from a broad role; it only enforces high-level constraints.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a custom IAM role in GCP?
Open an interactive chat with Bash
Why is sharing a service account key discouraged?
Open an interactive chat with Bash
What is the principle of least privilege in IAM?
Open an interactive chat with Bash
What is a custom IAM role in GCP?
Open an interactive chat with Bash
What is the principle of least privilege?
Open an interactive chat with Bash
Why is it discouraged to distribute service account keys?
Open an interactive chat with Bash
GCP Associate Cloud Engineer
Setting up a cloud solution environment
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .