GCP Professional Cloud Architect Practice Question

Your company uses a host project to provide Shared VPC networks and a separate service project for a GKE workload. To enforce separation of duties, network engineers must be able to create and modify subnets and firewall rules only in the host project, while application engineers deploy and update GKE clusters in the service project but must not change network settings. Which approach best meets these requirements and follows the principle of least privilege?

  • Grant network engineers the Compute Network Admin role on the host project and no roles on the service project; grant application engineers the Kubernetes Engine Admin role on the service project and the Compute Network User role on the host project.

  • Place both teams in a single project and assign network engineers Compute Network Admin while application engineers get Kubernetes Engine Admin.

  • Grant network engineers the Organization-level Network Admin role; grant application engineers the Project Editor role on the service project only.

  • Grant network engineers the Compute Security Admin role on the host project; grant application engineers the Kubernetes Engine Cluster Viewer role on the service project.

GCP Professional Cloud Architect
Designing for security and compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot