GCP Professional Cloud Architect Practice Question
Your company uses a host project to provide Shared VPC networks and a separate service project for a GKE workload. To enforce separation of duties, network engineers must be able to create and modify subnets and firewall rules only in the host project, while application engineers deploy and update GKE clusters in the service project but must not change network settings. Which approach best meets these requirements and follows the principle of least privilege?
Grant network engineers the Compute Network Admin role on the host project and no roles on the service project; grant application engineers the Kubernetes Engine Admin role on the service project and the Compute Network User role on the host project.
Place both teams in a single project and assign network engineers Compute Network Admin while application engineers get Kubernetes Engine Admin.
Grant network engineers the Organization-level Network Admin role; grant application engineers the Project Editor role on the service project only.
Grant network engineers the Compute Security Admin role on the host project; grant application engineers the Kubernetes Engine Cluster Viewer role on the service project.
Compute Network Admin on the host project lets the network team manage subnets and firewall rules without giving them permissions to create or run workloads. Application engineers need Kubernetes Engine Admin on the service project to create and manage clusters, and Compute Network User on the host project so their cluster-creation requests can attach to Shared VPC subnets. They receive no permissions on the host project that would allow them to alter network configurations, and the network team receives no roles on the service project, achieving clean separation of duties. The other options either grant overly broad roles (Organization-level Network Admin or Project Editor), omit required permissions to create clusters, or eliminate the project boundary that enforces separation.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Shared VPC in GCP?
Open an interactive chat with Bash
What does the principle of least privilege mean in the context of GCP roles?
Open an interactive chat with Bash
How do the Compute Network Admin and Kubernetes Engine Admin roles differ?
Open an interactive chat with Bash
What is a Shared VPC in GCP?
Open an interactive chat with Bash
What are the specific permissions provided by the Compute Network User role?
Open an interactive chat with Bash
Why is the principle of least privilege important in GCP role assignments?
Open an interactive chat with Bash
GCP Professional Cloud Architect
Designing for security and compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .