Your organization just created a new development project. A junior developer needs to create, start, stop, and delete Compute Engine VM instances and manage attached persistent disks, but must not be able to alter VPC networks, firewalls, or IAM policies. You want to follow the principle of least privilege while keeping administration simple. Which single IAM role should you grant to the developer on the project?
Create a custom role with compute.instances.* permissions and assign it to the developer.
Grant the predefined Compute Admin role (roles/compute.admin) on the project.
Grant the predefined Compute Instance Admin role (roles/compute.instanceAdmin.v1) on the project.
Grant the primitive Editor role (roles/editor) on the project.
The Compute Engine Instance Admin predefined role (roles/compute.instanceAdmin.v1) grants full lifecycle control over VM instances and their attached disks without including permissions to manage networks, firewall rules, or IAM policies. The broader Compute Admin role also allows VPC and firewall management, violating least-privilege. The primitive Editor role is even broader, spanning every enabled API in the project. Creating a custom role would work but is unnecessary because a Google-managed predefined role already fits the requirement.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the principle of least privilege in IAM?
Open an interactive chat with Bash
What permissions are provided by the Compute Instance Admin role?
Open an interactive chat with Bash
Why is a custom IAM role unnecessary in this scenario?
Open an interactive chat with Bash
What is an IAM role in GCP?
Open an interactive chat with Bash
What does the Compute Instance Admin role allow?
Open an interactive chat with Bash
Why is creating a custom role not the best option?
Open an interactive chat with Bash
GCP Associate Cloud Engineer
Setting up a cloud solution environment
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .