GCP Professional Cloud Architect Practice Question
CheapCorp's resource hierarchy is Organization → Folder "Prod" → Project "acme-prod". IAM policies are configured as follows: (1) the organization has no bindings for [email protected]; (2) on the Prod folder, [email protected] is granted roles/storage.objectAdmin, and an IAM deny policy explicitly denies the permission storage.objects.delete for alice; (3) on the project, [email protected] is granted roles/storage.objectViewer; (4) the bucket inside the project has no additional bindings. When Alice executes gsutil rm gs://reports-prod/payroll.csv, what is the outcome of the policy evaluation?
The request is denied because the explicit deny on storage.objects.delete at the folder overrides the allow granted by roles/storage.objectAdmin.
The request succeeds because bucket permissions inherit only from the project, and there is no deny defined at the project level.
The request succeeds because roles/storage.objectAdmin at the folder grants delete and overrides the deny that is set at the same level.
The request is denied because roles/storage.objectViewer does not include delete and higher-level roles are not evaluated during access checks.
The delete request fails. Although roles/storage.objectAdmin (granted at the folder) normally includes storage.objects.delete, an IAM deny always takes precedence over any allows that are inherited or defined at the same or lower level in the resource hierarchy. Because the deny policy is attached to the Prod folder, every project and bucket beneath that folder inherits the denial, so the operation is blocked despite any allow bindings present elsewhere.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an IAM Deny Policy?
Open an interactive chat with Bash
How does resource hierarchy affect IAM policy evaluation?
Open an interactive chat with Bash
What is the difference between roles/storage.objectAdmin and roles/storage.objectViewer?
Open an interactive chat with Bash
GCP Professional Cloud Architect
Designing for security and compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .